Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
3369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.64% | 💥 PoC | EthpressAI | 23/9/2026 | 24/9/2026 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a… | |
| Aplazada | Alta (8.1) | 0.13% | — | Publishpress CapabilitiesAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. | |
| Aplazada | Media (6.4) | 0.26% | — | Motopress GetwidAI | 23/9/2026 | 23/9/2026 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-controlled block content in the frontend JavaScript mapStyles() function. This makes… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | ReactpressAI | 22/9/2026 | 23/9/2026 | ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing… | |
| Analizada | Alta (8.1) | 46% | ⚠ Explotación activa💥 Exploit | Wordpress | 22/9/2026 | 28/9/2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | |
| Aplazada | Alta (7.6) | 0.38% | — | Devitems Hashbar Wordpress Notification BARAI | 22/9/2026 | 22/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | |
| Aplazada | Media (4.3) | 0.35% | — | ThumbpressAI | 22/9/2026 | 22/9/2026 | The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.53% | — | Cozmoslabs TranslatepressAI | 22/9/2026 | 23/9/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This… | |
| Pendiente de análisis | Media (5.3) | 0.17% | — | Espressif Esp-hostedAI | 21/9/2026 | 22/9/2026 | The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to pb_istream_from_buffer(frame.data_value, frame.data_length) without… | |
| Aplazada | Media (5.3) | 0.32% | — | Magnigenie RestropressAI | 21/9/2026 | 21/9/2026 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero. | |
| Aplazada | Baja (3.7) | 0.24% | — | Tiktok Wordpress PluginAI | 20/9/2026 | 22/9/2026 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Aplazada | Media (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… | |
| Aplazada | Alta (7.2) | 0.50% | — | Photo Gallery Sliders Proofing WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator… | |
| Aplazada | Alta (8.1) | 0.65% | — | ProfilepressAI | 19/9/2026 | 21/9/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not… | |
| Aplazada | Media (4.3) | 0.18% | — | Presscustomizr Nimble Page BuilderAI | 19/9/2026 | 21/9/2026 | The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts… | |
| Aplazada | Media (6.1) | 0.37% | — | Wpdeveloper EmbedpressAI | 18/9/2026 | 18/9/2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.1) | 0.38% | 💥 PoC | WordpressAI | 18/9/2026 | 19/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through… | |
| Aplazada | Media (6.5) | 0.27% | — | Magnigenie RestropressAI | 18/9/2026 | 18/9/2026 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order. | |
| Aplazada | Media (5.4) | 0.14% | — | Publishpress SeriesAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Crítica (9.8) | 0.63% | — | PressengineAI | 17/9/2026 | 18/9/2026 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators. |