Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2634▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Openai Chatbot FOR Wordpress HelperAI | 2/7/2026 | 5/10/2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simple PAY WordpressAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Alta (8.7) | 0.63% | — | Wordpress Time CapsuleAI | 20/6/2026 | 29/9/2026 | WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the… | |
| Aplazada | Alta (8.6) | 0.26% | — | Wordpress Dating ThemeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. | |
| Aplazada | Alta (8.8) | 0.18% | — | Wordpress Dating ThemeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 5/10/2026 | Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Crítica (10) | 0.43% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 5/10/2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Geomywp GEO MY WordpressAI | 16/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elex Wordpress Helpdesk & Customer Ticketing SystemAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. | |
| Aplazada | Media (6.9) | 0.13% | — | Wordpress More FieldsAI | 15/6/2026 | 17/6/2026 | WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit… | |
| Aplazada | Media (6.9) | 0.69% | — | Wordpress Imdb Profile WidgetAI | 15/6/2026 | 17/6/2026 | WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.php containing… | |
| Aplazada | Alta (8.7) | 0.32% | — | Wpultimate Wordpress Ultimate Product CatalogAI | 15/6/2026 | 17/6/2026 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file… | |
| Aplazada | Media (5.3) | 0.10% | — | Wordpress Lazy Content SliderAI | 15/6/2026 | 17/6/2026 | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify… | |
| Aplazada | Media (5.1) | 0.22% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts… | |
| Aplazada | Alta (8.8) | 0.24% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL… | |
| Aplazada | Alta (8.8) | 0.30% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter… | |
| Pendiente de análisis | Crítica (9.9) | 0.74% | — | Cpanel Wordpress ToolkitAI | 12/6/2026 | 17/6/2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | |
| Aplazada | Crítica (9.3) | 0.84% | — | Wordpress Background Image CropperAI | 8/6/2026 | 23/7/2026 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary code on the server. | |
| Aplazada | Alta (8.7) | 0.53% | — | Wordpress Augmented RealityAI | 8/6/2026 | 23/7/2026 | WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files… | |
| Aplazada | Media (5.1) | 0.17% | — | Wordpress Popup BuilderAI | 4/6/2026 | 22/7/2026 | WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title… | |
| Aplazada | Media (6.5) | 0.33% | — | Strategy11 Another Wordpress Classifieds PluginAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5. | |
| Aplazada | Media (6.4) | 0.26% | — | Team Master Modern Wordpress Team Showcase Team MasterAI | 27/5/2026 | 17/6/2026 | The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wordpress Ultimate Form Builder LiteAI | 23/5/2026 | 23/7/2026 | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Alta (8.7) | 0.64% | — | Google Drive FOR WordpressAI | 17/5/2026 | 17/6/2026 | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name… |