Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.59% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.60% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.60% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform… | |
| Modificada | Media (5.4) | 0.57% | — | Bplugins Html5 Audio Player | 6/2/2023 | 17/6/2026 | The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.59% | — | Pickplugins Breadcrumb | 6/2/2023 | 17/6/2026 | The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.4) | 0.65% | — | Goldplugins Easy Testimonials | 6/2/2023 | 17/6/2026 | The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Analizada | Media (5.4) | 0.53% | — | Pwrplugins Portfolio FOR Elementor | 30/1/2023 | 17/6/2026 | El complemento Portfolio for Elementor de WordPress anterior a 2.3.1 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían ser utilizados… | |
| Modificada | Crítica (9.8) | 1.6% | — | Pickplugins User Verification | 23/1/2023 | 17/6/2026 | El complemento User Verification de WordPress anterior a la versión 1.0.94 se vio afectado por una vulnerabilidad de seguridad de Auth Bypass. Para evitar la autenticación, sólo necesitamos saber el nombre de usuario del usuario. Dependiendo de qué nombre de usuario conozcamos, que se puede consultar fácilmente porque… | |
| Modificada | Media (5.4) | 0.47% | — | Gsplugins GS Logo Slider | 23/1/2023 | 17/6/2026 | El complemento GS Logo Slider de WordPress anterior a 3.3.8 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían ser utilizado contra… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Fullworksplugins Quick Event Manager | 20/1/2023 | 17/6/2026 | El complemento Quick Event Manager de WordPress, versión < 9.7.5, se ve afectado por una vulnerabilidad de cross site scripting reflejado en el parámetro 'category' de su acción 'qem_ajax_calendar'. | |
| Modificada | Media (5.4) | 0.37% | — | Warfareplugins Social Warfare | 19/1/2023 | 17/6/2026 | El complemento Social Warfare para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 4.4.0 incluida. Esto se debe a una validación nonce faltante o incorrecta en varias acciones AJAX. Esto hace posible que atacantes no autenticados eliminen la metainformación de la publicación y restablezcan… | |
| Modificada | Media (5.4) | 0.76% | — | Warfareplugins Social Warfare | 19/1/2023 | 17/6/2026 | El complemento Social Warfare para WordPress es vulnerable a la omisión de autorización debido a una falta de verificación de capacidad en varias acciones AJAX en versiones hasta la 4.3.0 incluida. Esto hace posible que los atacantes autenticados, con permisos de nivel de suscriptor y superiores, eliminen la… | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | PHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+2 | 26/12/2022 | 17/6/2026 | php-mod/curl (un contenedor de la extensión PHP cURL) anterior a 2.3.2 permite XSS a través del parámetro clave post_file_path_upload.php y los datos POST en post_multidimensional.php. | |
| Modificada | Media (6.1) | 0.57% | — | Yikesplugins Easy Forms FOR Mailchimp | 12/12/2022 | 17/6/2026 | Una vulnerabilidad ha sido encontrada en yikes-inc-easy-mailchimp-extender Plugin hasta 6.8.5 y clasificada como problemática. Esto afecta a una parte desconocida del archivo admin/partials/ajax/add_field_to_form.php. La manipulación del argumento field_name/merge_tag/field_type/list_id conduce a Cross-Site Scripting.… | |
| Modificada | Media (6.1) | 0.55% | — | Fivestarplugins Five Star Restaurant Reservations | 21/11/2022 | 17/6/2026 | El complemento de WordPress Five Star Restaurant Reservations anterior a 2.4.12 no tiene autorización para cambiar si un pago fue exitoso o fallido, lo que permite a usuarios no autenticados cambiar el estado de pago de reservas arbitrarias. Además, debido a la falta de sanitización y escape, los atacantes podrían… | |
| Modificada | Media (4.3) | 0.53% | — | Richplugins Plugin FOR Google Reviews | 18/11/2022 | 17/6/2026 | Vulnerabilidad de control de acceso roto autenticada (con permisos de suscriptores o superiores) en el complemento Plugin para Google Reviews en WordPress en versiones <= 2.2.2. |