Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Coolplugins Process Steps Template Designer | 12/7/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request… | |
| Modificada | Media (4.3) | 0.38% | — | Goldplugins Custom Banners | 12/7/2023 | 17/6/2026 | The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted… | |
| Modificada | Media (4.3) | 0.39% | — | Goldplugins Staff Directory Plugin | 1/7/2023 | 17/6/2026 | The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… | |
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Easy Testimonials | 1/7/2023 | 17/6/2026 | The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… | |
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Locations | 1/7/2023 | 17/6/2026 | The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to update custom field meta data via a forged request… | |
| Modificada | Media (4.3) | 0.48% | — | Coolplugins Cool Timeline | 1/7/2023 | 17/6/2026 | The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a… | |
| Modificada | Alta (8.8) | 0.73% | — | Smartypantsplugins SP Project & Document Manager | 30/6/2023 | 17/6/2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for… | |
| Modificada | Media (5.4) | 0.35% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check on the ajax_store_save() function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.25% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing nonce validation on the ajax_store_save() function. This makes it possible for unauthenticated attackers to modify… | |
| Modificada | Media (4.8) | 0.37% | — | Aviplugins WP Register Profile With Shortcode | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Galleryplugins Video Contest | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions. | |
| Modificada | Media (4.3) | 0.29% | — | Wickedplugins Wicked Folders | 9/6/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Alta (8.8) | 0.56% | — | Coolplugins Process Steps Template Designer | 7/6/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such… | |
| Modificada | Alta (8.8) | 0.33% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | El plugin Feather Login Page para WordPress es vulnerable a Cross-Site Request Forgery en versiones desde la 1.0.7 hasta la 1.1.1 inclusive. Esto es debido a la falta de validación nonce en la función "createTempAccountLink". Esto hace posible que atacantes no autenticados puedan crear un nuevo usuario con rol de… | |
| Modificada | Media (5.4) | 0.44% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | El plugin Feather Login Page para WordPress es vulnerable a la pérdida no autorizada de datos debido a una falta de capacidad de comprobación en la función "deleteUser" en las versiones a partir de la 1.0.7 hasta la 1.1.1 inclusive. Esto hace posible que atacantes autenticados con permisos de nivel de suscriptor y… | |
| Modificada | Alta (8.8) | 0.71% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Fooplugins Foogallery | 16/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. | |
| Modificada | Media (6.5) | 0.32% | — | Wpplugins Hide MY WP Ghost | 9/5/2023 | 17/6/2026 | The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For… | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Plainviewplugins Mycryptocheckout | 2/5/2023 | 17/6/2026 | The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Fullworksplugins Quick Contact Form | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | |
| Modificada | Alta (7.5) | 0.52% | — | Freesoul Deactivate Plugins - Plugin Manager AND Cleanup Project Freesoul Deactivate Plugins - Plugin Manager AND Cleanup | 16/4/2023 | 17/6/2026 | Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions. |