Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Thememylogin Theme MY LoginAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. | |
| Aplazada | Crítica (9.1) | 0.42% | — | OTP Login With Phone NumberAI | 5/8/2026 | 26/8/2026 | The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can… | |
| Aplazada | Alta (7.5) | 0.55% | — | Login-socialAI | 2/8/2026 | 26/8/2026 | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account,… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 1/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at… | |
| Aplazada | Media (6.5) | 0.27% | — | Authora Easy Login With Mobile NumberAI | 1/8/2026 | 26/8/2026 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know… | |
| Aplazada | Media (6.3) | 0.24% | — | Grav Login PluginAI | 29/7/2026 | 30/7/2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout… | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Social Login AND RegisterAI | 29/7/2026 | 30/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any… | |
| Aplazada | Media (6.5) | 0.22% | — | Wordpress Social Login AND RegisterAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |
| Aplazada | Crítica (9.1) | 0.45% | — | Wechat Qrcode LoginAI | 27/7/2026 | 27/7/2026 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem… | |
| Aplazada | Alta (8.8) | 0.25% | — | Wpo365 LoginAI | 23/7/2026 | 24/7/2026 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options'… | |
| Aplazada | Crítica (9.1) | 0.43% | — | Regularlabs IP LoginAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. | |
| Aplazada | Alta (7.5) | 0.35% | — | Regularlabs IP LoginAI | 22/7/2026 | 28/7/2026 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | Getgrav Grav LoginAI | 22/7/2026 | 22/7/2026 | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data… | |
| Aplazada | Alta (8.1) | 0.38% | — | Social Login Passkeys Magic Link Email OTPAI | 20/7/2026 | 21/7/2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email… | |
| Aplazada | Baja (2.3) | 0.14% | — | Getgrav Grav-plugin-loginAI | 17/7/2026 | 17/7/2026 | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce or Origin/Referer check. Because Grav core dispatches the task from… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Happy Coders OTP LoginAI | 16/7/2026 | 16/7/2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new… | |
| Aplazada | Alta (8.2) | 0.32% | — | Favethemes Houzez Login RegisterAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3. | |
| Aplazada | Alta (8.8) | 0.74% | — | Simple JWT LoginAI | 11/7/2026 | 13/7/2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT… | |
| Analizada | Media (5.4) | 0.28% | — | Budda Login Disable | 10/7/2026 | 6/8/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4. | |
| Aplazada | Crítica (9.8) | 0.89% | — | Miniorange Social Login AND RegisterAI | 10/7/2026 | 13/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST… | |
| Aplazada | Alta (8.1) | 0.56% | — | Loginpress PROAI | 10/7/2026 | 10/7/2026 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me endpoint and using it directly with… | |
| Aplazada | Alta (8.1) | 0.57% | — | Loginpress PROAI | 10/7/2026 | 10/7/2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array returned by GitHub's… | |
| Aplazada | Alta (8.1) | 0.56% | — | Loginpress PROAI | 10/7/2026 | 10/7/2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Miniorange OTP Login Verification AND SMS NotificationsAI | 9/7/2026 | 9/7/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the… |