Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
509 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.47% | — | Blocks FOR ACF FieldsAI | 9/7/2026 | 9/7/2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Creativethemes Blocksy CompanionAI | 9/7/2026 | 9/7/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring… | |
| Aplazada | Crítica (9.2) | 3.6% | — | Blocksy Companion PROAI | 8/7/2026 | 8/7/2026 | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom… | |
| Aplazada | Media (6.4) | 0.26% | — | Posimyth Nexter BlocksAI | 8/7/2026 | 8/7/2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.36% | — | GenerateblocksAI | 3/7/2026 | 6/7/2026 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (10) | 0.86% | — | Blocksy Companion PROAI | 2/7/2026 | 2/7/2026 | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | |
| Aplazada | Media (4.3) | 0.34% | — | Qodeinteractive QI BlocksAI | 1/7/2026 | 1/7/2026 | The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored… | |
| Aplazada | Media (4.3) | 0.45% | — | Kadence BlocksAI | 1/7/2026 | 1/7/2026 | The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in the Optimize_Rest_Controller's… | |
| Aplazada | Media (4.3) | 0.47% | — | Kadence BlocksAI | 1/7/2026 | 1/7/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.22% | — | Themegrill Magazine BlocksAI | 26/6/2026 | 26/6/2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Blocksy Companion PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. | |
| Aplazada | Alta (8.5) | 0.58% | — | Blocksy Companion PROAI | 26/6/2026 | 26/6/2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Wpdeveloper Essential BlocksAI | 25/6/2026 | 25/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.32% | — | MIR Blocks AND ShortcodesAI | 24/6/2026 | 30/6/2026 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of the 'msc_stats' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on… | |
| Aplazada | Media (4.4) | 0.34% | — | Creativethemes Blocksy CompanionAI | 19/6/2026 | 22/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject… | |
| Aplazada | Media (4.3) | 0.32% | — | Kadence BlocksAI | 18/6/2026 | 18/6/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Travel Gutenberg BlocksAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4. | |
| Aplazada | Crítica (9.9) | 0.79% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | B BlocksAI | 15/6/2026 | 17/6/2026 | Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. | |
| Aplazada | Alta (8.8) | 1.6% | — | Creativethemes BlocksyAI | 9/6/2026 | 23/7/2026 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which… | |
| Aplazada | Media (6.4) | 0.35% | — | Recipe Card Blocks LiteAI | 8/6/2026 | 23/7/2026 | The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into… | |
| Aplazada | Alta (7.2) | 0.26% | — | Wpdeveloper Essential BlocksAI | 5/6/2026 | 23/7/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (6.5) | 0.37% | — | GenerateblocksAI | 27/5/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. | |
| Aplazada | Media (5.4) | 0.41% | — | Nexa BlocksAI | 20/5/2026 | 24/7/2026 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it… |