Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1874 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.45%—Select-themes Select CoreAI9/12/20257/10/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP vulnerabilidad ('inclusión remota de ficheros PHP') en Select-Themes Select Core select-core permite la inclusión local de ficheros PHP. Este problema afecta a Select Core: desde n/a hasta < 2.6.
AplazadaMedia (4.3)0.21%—Elated-themes THE AisleAI9/12/20257/10/2026
Vulnerabilidad por falta de autorización en Elated-Themes The Aisle theaisle permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a The Aisle: desde n/a hasta menor o igual que 2.9.
AplazadaMedia (6.5)0.23%—P-themes Porto ThemeAI9/12/20257/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en p-themes Porto Theme - Functionality porto-functionality permite XSS Almacenado. Este problema afecta a Porto Theme - Functionality: desde n/a hasta menor o igual que 3.6.2.
ModificadaMedia (6.5)0.20%—Vibethemes Wordpress Learning Management System9/12/20257/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en VibeThemes WPLMS wplms_plugin permite XSS Basado en DOM. Este problema afecta a WPLMS: desde n/a hasta menor o igual que 1.9.9.5.4.
AplazadaMedia (4.9)0.17%—Themesinflow Hercules CoreAI9/12/20257/10/2026
Vulnerabilidad de Falsificación de Petición del Lado del Servidor (SSRF) en ThemesInflow Hercules Core hercules-core permite la falsificación de petición del lado del servidor. Este problema afecta a Hercules Core: desde n/a hasta menor o igual que 7.4.
AplazadaAlta (7.5)0.46%—Fuelthemes North PluginAI9/12/20257/10/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en el plugin north-plugin de fuelthemes North - Required Plugin permite la inclusión local de ficheros PHP. Este problema afecta a North - Required Plugin: desde n/a hasta…
AplazadaMedia (5.3)0.22%—Everestthemes Everest BackupAI3/12/202517/6/2026
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.37%—Designthemes LMSAI2/12/202517/6/2026
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the…
AplazadaAlta (8.8)0.55%—Stylemixthemes Cost Calculator BuilderAI2/12/202517/6/2026
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders that…
AplazadaMedia (6.3)0.26%—Favethemes HouzezAI26/11/202517/6/2026
The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is…
AplazadaMedia (6.1)0.21%—Favethemes HouzezAI26/11/202517/6/2026
The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for…
AplazadaMedia (6.5)0.20%—Envothemes Envo ExtraAI21/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Extra: from n/a through <= 1.9.11.
AplazadaMedia (6.5)0.19%—Bold-themes Bold Page BuilderAI21/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2.
AplazadaAlta (7.1)0.31%💥 PoCFlothemes FLO FormsAI21/11/20258/10/2026
El plugin Flo Forms - Easy Drag & Drop Form Builder para WordPress es vulnerable a cross-site scripting almacenado a través de cargas de archivos SVG en todas las versiones hasta la 1.0.43, inclusive. Esto se debe a que el plugin permite cargas de archivos SVG a través de un endpoint AJAX no autenticado…
AplazadaMedia (5.3)0.31%—Yithemes Yith Woocommerce WishlistAI19/11/202517/6/2026
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback…
AplazadaMedia (5.3)0.28%—Yithemes Yith Woocommerce WishlistAI19/11/202517/6/2026
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's…
ModificadaMedia (6.5)0.11%—Hasthemes WP Plugin Manager13/11/20257/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en HasThemes WP Plugin Manager wp-plugin-manager permite la falsificación de petición en sitios cruzados. Este problema afecta a WP Plugin Manager: desde n/a hasta menor o igual que 1.4.7.
AplazadaAlta (7.5)0.26%—Stylemixthemes BookitAI12/11/202517/6/2026
The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated…
AplazadaAlta (8.8)0.69%—Creativethemes Blocksy CompanionAI11/11/202517/6/2026
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes…
AplazadaMedia (6.4)0.24%—Athemes Addons FOR ElementorAI8/11/20257/10/2026
El plugin aThemes Addons para Elementor para WordPress es vulnerable a cross-site scripting almacenado a través del widget Call To Action en versiones hasta la 1.1.5, inclusive, debido a la sanitización de entrada y el escape de salida insuficientes en los valores proporcionados por el usuario. Esto hace posible que…
AplazadaAlta (8.1)0.43%—Edge-themes AlloggioAI6/11/202517/6/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP Vulnerabilidad de control ('Inclusión Remota de Ficheros PHP') en Edge-Themes Alloggio - Hotel Booking alloggio permite Inclusión Local de Ficheros PHP. Este problema afecta a Alloggio - Hotel Booking: desde n/a hasta menor…
AplazadaCrítica (9.8)0.42%—Elated-themes Search AND GOAI6/11/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows Password Recovery Exploitation.This issue affects Search & Go: from n/a through <= 2.7.
AplazadaCrítica (9.9)0.45%—Case-themes Case AddonsAI6/11/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects Case Addons: from n/a through < 1.3.0.
AplazadaAlta (7.5)0.49%—Zozothemes ZegenAI6/11/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Zegen zegen allows PHP Local File Inclusion.This issue affects Zegen: from n/a through <= 1.1.9.
AplazadaCrítica (9.8)0.50%—Victorthemes SeilAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1.