Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

3369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.64%💥 PoCEthpressAI23/9/202624/9/2026
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a…
AplazadaAlta (8.1)0.13%—Publishpress CapabilitiesAI23/9/202623/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.
AplazadaMedia (6.4)0.26%—Motopress GetwidAI23/9/202623/9/2026
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-controlled block content in the frontend JavaScript mapStyles() function. This makes…
Pendiente de análisisAlta (7.5)0.53%—ReactpressAI22/9/202623/9/2026
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing…
AnalizadaAlta (8.1)46%⚠ Explotación activa💥 ExploitWordpress22/9/202628/9/2026
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
AplazadaAlta (7.6)0.38%—Devitems Hashbar Wordpress Notification BARAI22/9/202622/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.
AplazadaMedia (4.3)0.35%—ThumbpressAI22/9/202622/9/2026
The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for…
AplazadaAlta (7.2)0.53%—Cozmoslabs TranslatepressAI22/9/202623/9/2026
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This…
Pendiente de análisisMedia (5.3)0.17%—Espressif Esp-hostedAI21/9/202622/9/2026
The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to pb_istream_from_buffer(frame.data_value, frame.data_length) without…
AplazadaMedia (5.3)0.32%—Magnigenie RestropressAI21/9/202621/9/2026
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
AplazadaBaja (3.7)0.24%—Tiktok Wordpress PluginAI20/9/202622/9/2026
The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
AplazadaMedia (4.2)0.19%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including…
AplazadaAlta (7.2)0.50%—Photo Gallery Sliders Proofing WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator…
AplazadaAlta (8.1)0.65%—ProfilepressAI19/9/202621/9/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not…
AplazadaMedia (4.3)0.18%—Presscustomizr Nimble Page BuilderAI19/9/202621/9/2026
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts…
AplazadaMedia (6.1)0.37%—Wpdeveloper EmbedpressAI18/9/202618/9/2026
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes…
AplazadaAlta (7.1)0.38%💥 PoCWordpressAI18/9/202619/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through…
AplazadaMedia (6.5)0.27%—Magnigenie RestropressAI18/9/202618/9/2026
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
AplazadaMedia (5.4)0.14%—Publishpress SeriesAI17/9/202617/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
AplazadaMedia (6.5)0.22%—Motopress Jetblocks FOR ElementorAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
AplazadaAlta (7.6)0.38%—Publishpress SeriesAI17/9/202619/9/2026
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
AplazadaMedia (6.5)0.22%—Publishpress SeriesAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
AplazadaCrítica (9.8)0.63%—PressengineAI17/9/202618/9/2026
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.