Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.57% | — | Ckeditor-wordcount-plugin Project Ckeditor-wordcount-plugin | 21/7/2023 | 17/6/2026 | ckeditor-wordcount-plugin es un complemento WordCount de código abierto para CKEditor. Se ha descubierto que el complemento `ckeditor-wordcount-plugin` para CKEditor4 es susceptible a Cross-Site Scripting al cambiar al modo de código fuente. Este problema se solucionó en la versión 1.17.12 del complemento… | |
| Modificada | Alta (7.5) | 16% | 💥 PoC | What3words Autosuggest | 18/7/2023 | 17/6/2026 | A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerability is the function enqueue_scripts of the file w3w-autosuggest/public/class-w3w-autosuggest-public.php of the component Setting Handler. The manipulation leads to… | |
| Modificada | Alta (8.8) | 0.25% | — | Replace Word Project Replace Word | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions. | |
| Modificada | Alta (7.2) | 0.93% | — | Webtoffee Import Export Wordpress Users | 18/7/2023 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop… | |
| Modificada | Crítica (9.6) | 2.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 11/7/2023 | 17/6/2026 | Microsoft Office Security Feature Bypass Vulnerability | |
| Analizada | Alta (8.8) | 0.30% | — | Vibethemes Wordpress Learning Management System | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Wpmobilepack Wordpress Mobile Pack | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Video Contest Wordpress Project Video Contest Wordpress | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions. | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Media (4.8) | 0.55% | — | Kanbanwp Kanban Boards FOR Wordpress | 27/6/2023 | 17/6/2026 | The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.40% | — | Wpexperts Password Protected | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Alta (7.5) | 1.7% | — | Word-wrap Project Word-wrap | 22/6/2023 | 17/6/2026 | All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable. | |
| Modificada | Media (6.1) | 0.39% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 20/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Iksweb Wordpress Ctapt | 15/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions. | |
| Modificada | Media (5.5) | 0.38% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.9) | 1.7% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)… | |
| Modificada | Media (5.4) | 0.36% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Media (4.3) | 0.41% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Wordpress Vertical Image Slider | 9/6/2023 | 17/6/2026 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Valvepress Wordpress Automatic Plugin | 7/6/2023 | 17/6/2026 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a… |