Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.52%—Themeisle WP Maintenance Mode & Coming Soon11/7/202217/6/2026
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
ModificadaMedia (6.1)0.79%—Site Offline OR Coming Soon Project Site Offline OR Coming Soon27/6/202217/6/2026
The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF…
ModificadaMedia (4.8)0.59%—Colorlib Coming Soon & Maintenance Mode20/6/202217/6/2026
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.80%—Subsystic Coming Soon25/4/202217/6/2026
The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.88%—Edmonsoft Countdown, Coming Soon, Maintenance - Countdown & Clock14/3/202217/6/2026
The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (4.3)0.47%—Wpdevart Coming Soon AND Maintenance Mode21/2/202217/6/2026
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
ModificadaMedia (4.3)0.35%—Wpdevart Coming Soon AND Maintenance Mode21/2/202217/6/2026
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (4.8)0.59%—Dazzlersoftware Coming Soon, Under Construction & Maintenance Mode BY Dazzler1/11/202117/6/2026
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored…
ModificadaMedia (5.4)0.62%—Wpdevart Coming Soon AND Maintenance Mode11/10/202117/6/2026
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
ModificadaAlta (8.8)1.3%—Wpshopmart Coming Soon Page & Maintenance Mode14/5/202117/6/2026
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps…
ModificadaMedia (5.4)3.8%💥 ExploitSeedprod Coming Soon Page, Under Construction & Maintenance Mode24/6/202017/6/2026
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
ModificadaAlta (7.6)2.0%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
ModificadaMedia (5.4)1.1%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
ModificadaAlta (8.8)0.92%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php bg_color parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_height parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php social_icon_1 parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php button_text_link parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_title parameter.
ModificadaAlta (8.8)0.64%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title_icon parameter.
Orbitaley — Vulnerabilidades