Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Halgatewood Dashicons + Custom Post Types21/12/202317/6/2026
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
ModificadaCrítica (9.8)0.77%—Mypresta Product TAG Icons PRO6/12/202317/6/2026
In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaMedia (5.4)0.38%—Cybernetikz Easy Social Icons30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy Social Icons allows Stored XSS.This issue affects Easy Social Icons: from n/a through 3.2.4.
ModificadaMedia (5.4)0.39%—Vyasdipen TOP 25 Social Icons8/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions.
ModificadaAlta (8.8)0.54%—Bplugins Icons Font Loader6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
ModificadaAlta (7.2)1.0%—Bplugins Icons Font Loader2/11/202317/6/2026
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the…
ModificadaAlta (8.8)0.22%—Ultimatelysocial Social Media Share Buttons & Social Sharing Icons20/10/202317/6/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated…
ModificadaMedia (6.5)1.2%💥 PoCUltimatelysocial Social Media Share Buttons & Social Sharing Icons20/10/202317/6/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well…
ModificadaMedia (4.8)0.37%—Uniconsent CMP FOR Gdpr Cpra GPP TCF2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in UniConsent UniConsent CMP for GDPR CPRA GPP TCF plugin <= 1.4.2 versions.
ModificadaMedia (5.4)0.41%—Webguysaz Font Awesome More Icons28/9/202317/6/2026
The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and…
ModificadaMedia (6.1)0.41%—Ultimatelysocial Social Media Share Buttons & Social Sharing Icons27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions.
ModificadaMedia (4.3)0.61%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+628/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.5)0.69%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+728/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,…
ModificadaAlta (8.8)0.26%—Social Media Icons Widget Project Social Media Icons Widget18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <= 1.6 versions.
ModificadaMedia (6.1)0.55%—Woocommerce Icons FOR Features30/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be…
ModificadaMedia (5.4)0.38%—Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
ModificadaAlta (8.8)0.26%—Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
ModificadaAlta (7.2)24%—WP SVG Icons Project WP SVG Icons13/6/202217/6/2026
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
ModificadaMedia (4.8)0.60%—Cybernetikz Easy Social Icons11/4/202217/6/2026
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.2)1.3%—Cybernetikz Easy Social Icons4/4/202217/6/2026
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
ModificadaMedia (5.4)0.60%—Freshlightlab Menu Image, Icons Made Easy28/3/202217/6/2026
The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads…
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.1)2.3%💥 ExploitCybernetikz Easy Social Icons2/9/202117/6/2026
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.
ModificadaMedia (5.4)0.62%—Thememason Popular Brand Icons - Simple Icons2/8/202117/6/2026
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an…
ModificadaAlta (8.8)1.3%—Accesspressthemes Accesspress Social Icons18/3/202117/6/2026
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
Orbitaley — Vulnerabilidades