Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1874 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.45% | — | Select-themes Select CoreAI | 9/12/2025 | 7/10/2026 | Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP vulnerabilidad ('inclusión remota de ficheros PHP') en Select-Themes Select Core select-core permite la inclusión local de ficheros PHP. Este problema afecta a Select Core: desde n/a hasta < 2.6. | |
| Aplazada | Media (4.3) | 0.21% | — | Elated-themes THE AisleAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad por falta de autorización en Elated-Themes The Aisle theaisle permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a The Aisle: desde n/a hasta menor o igual que 2.9. | |
| Aplazada | Media (6.5) | 0.23% | — | P-themes Porto ThemeAI | 9/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en p-themes Porto Theme - Functionality porto-functionality permite XSS Almacenado. Este problema afecta a Porto Theme - Functionality: desde n/a hasta menor o igual que 3.6.2. | |
| Modificada | Media (6.5) | 0.20% | — | Vibethemes Wordpress Learning Management System | 9/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en VibeThemes WPLMS wplms_plugin permite XSS Basado en DOM. Este problema afecta a WPLMS: desde n/a hasta menor o igual que 1.9.9.5.4. | |
| Aplazada | Media (4.9) | 0.17% | — | Themesinflow Hercules CoreAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de Falsificación de Petición del Lado del Servidor (SSRF) en ThemesInflow Hercules Core hercules-core permite la falsificación de petición del lado del servidor. Este problema afecta a Hercules Core: desde n/a hasta menor o igual que 7.4. | |
| Aplazada | Alta (7.5) | 0.46% | — | Fuelthemes North PluginAI | 9/12/2025 | 7/10/2026 | Control inadecuado del nombre de fichero para la declaración Include/Require en programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en el plugin north-plugin de fuelthemes North - Required Plugin permite la inclusión local de ficheros PHP. Este problema afecta a North - Required Plugin: desde n/a hasta… | |
| Aplazada | Media (5.3) | 0.22% | — | Everestthemes Everest BackupAI | 3/12/2025 | 17/6/2026 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Designthemes LMSAI | 2/12/2025 | 17/6/2026 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Alta (8.8) | 0.55% | — | Stylemixthemes Cost Calculator BuilderAI | 2/12/2025 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders that… | |
| Aplazada | Media (6.3) | 0.26% | — | Favethemes HouzezAI | 26/11/2025 | 17/6/2026 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is… | |
| Aplazada | Media (6.1) | 0.21% | — | Favethemes HouzezAI | 26/11/2025 | 17/6/2026 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.20% | — | Envothemes Envo ExtraAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Extra: from n/a through <= 1.9.11. | |
| Aplazada | Media (6.5) | 0.19% | — | Bold-themes Bold Page BuilderAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2. | |
| Aplazada | Alta (7.1) | 0.31% | 💥 PoC | Flothemes FLO FormsAI | 21/11/2025 | 8/10/2026 | El plugin Flo Forms - Easy Drag & Drop Form Builder para WordPress es vulnerable a cross-site scripting almacenado a través de cargas de archivos SVG en todas las versiones hasta la 1.0.43, inclusive. Esto se debe a que el plugin permite cargas de archivos SVG a través de un endpoint AJAX no autenticado… | |
| Aplazada | Media (5.3) | 0.31% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback… | |
| Aplazada | Media (5.3) | 0.28% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's… | |
| Modificada | Media (6.5) | 0.11% | — | Hasthemes WP Plugin Manager | 13/11/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en HasThemes WP Plugin Manager wp-plugin-manager permite la falsificación de petición en sitios cruzados. Este problema afecta a WP Plugin Manager: desde n/a hasta menor o igual que 1.4.7. | |
| Aplazada | Alta (7.5) | 0.26% | — | Stylemixthemes BookitAI | 12/11/2025 | 17/6/2026 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.69% | — | Creativethemes Blocksy CompanionAI | 11/11/2025 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes… | |
| Aplazada | Media (6.4) | 0.24% | — | Athemes Addons FOR ElementorAI | 8/11/2025 | 7/10/2026 | El plugin aThemes Addons para Elementor para WordPress es vulnerable a cross-site scripting almacenado a través del widget Call To Action en versiones hasta la 1.1.5, inclusive, debido a la sanitización de entrada y el escape de salida insuficientes en los valores proporcionados por el usuario. Esto hace posible que… | |
| Aplazada | Alta (8.1) | 0.43% | — | Edge-themes AlloggioAI | 6/11/2025 | 17/6/2026 | Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP Vulnerabilidad de control ('Inclusión Remota de Ficheros PHP') en Edge-Themes Alloggio - Hotel Booking alloggio permite Inclusión Local de Ficheros PHP. Este problema afecta a Alloggio - Hotel Booking: desde n/a hasta menor… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Elated-themes Search AND GOAI | 6/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows Password Recovery Exploitation.This issue affects Search & Go: from n/a through <= 2.7. | |
| Aplazada | Crítica (9.9) | 0.45% | — | Case-themes Case AddonsAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects Case Addons: from n/a through < 1.3.0. | |
| Aplazada | Alta (7.5) | 0.49% | — | Zozothemes ZegenAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Zegen zegen allows PHP Local File Inclusion.This issue affects Zegen: from n/a through <= 1.1.9. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Victorthemes SeilAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1. |