Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.37% | — | Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 24/7/2024 | 17/6/2026 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated… | |
| Analizada | Media (6.8) | 0.47% | — | Wpchill Image Photo Gallery Final Tiles Grid | 13/7/2024 | 17/6/2026 | The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high… | |
| Modificada | Media (5.3) | 0.53% | — | Wensolutions WP Child Theme Generator | 21/6/2024 | 17/6/2026 | The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it… | |
| Modificada | Media (4.3) | 0.28% | — | Wpchill Strong Testimonials | 7/6/2024 | 17/6/2026 | The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify… | |
| Modificada | Media (5.4) | 0.20% | — | Mainwp Child Reports | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1. | |
| Analizada | Media (4.8) | 0.40% | — | Wpchill Strong Testimonials | 24/4/2024 | 17/6/2026 | The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed | |
| Modificada | Media (4.8) | 0.34% | — | Wpchill Remove Footer Credit | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13. | |
| Aplazada | Media (5.4) | 0.20% | — | Catchplugins Generate Child ThemeAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0. | |
| Modificada | Media (5.4) | 0.50% | — | Wpchill Passster | 9/4/2024 | 17/6/2026 | The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.2) | 0.27% | — | ChilkatAI | 5/4/2024 | 17/6/2026 | Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function. | |
| Modificada | Alta (7.2) | 0.61% | — | Wpchill Download Monitor | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. | |
| Modificada | Alta (7.2) | 2.3% | 💥 Exploit | Wensolutions WP Child Theme Generator | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9. | |
| Modificada | Media (5.3) | 0.54% | — | Wpchill Simple Restrict | 13/3/2024 | 17/6/2026 | The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API. This makes it possible for authenticated attackers to bypass the plugin's restrictions to extract post titles and content | |
| Modificada | Media (5.3) | 0.48% | — | Wpchill Passster | 29/2/2024 | 17/6/2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Wpchill Download Monitor | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. | |
| Modificada | Alta (8.8) | 0.23% | — | Wpchill Strong Testimonials | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10. | |
| Modificada | Alta (8.8) | 0.91% | — | Wpchill Download Monitor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0. | |
| Modificada | Media (5.4) | 0.43% | — | Wpchill CPO Shortcodes | 22/11/2023 | 17/6/2026 | The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (4.9) | 0.65% | — | Wpchill Download Monitor | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. | |
| Modificada | Alta (8.8) | 0.25% | — | Sean-barton SB Child List | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Bestdivichild Business PRO | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Chilexpress-oficial | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <= 1.2.9 versions. | |
| Modificada | Alta (7.5) | 0.66% | — | Mainwp Child | 27/6/2023 | 17/6/2026 | The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a… | |
| Modificada | Media (5.4) | 0.38% | — | Wpchill Brilliance | 22/6/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions. |