Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

180 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.37%—Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI24/7/202417/6/2026
The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated…
AnalizadaMedia (6.8)0.47%—Wpchill Image Photo Gallery Final Tiles Grid13/7/202417/6/2026
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high…
ModificadaMedia (5.3)0.53%—Wensolutions WP Child Theme Generator21/6/202417/6/2026
The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it…
ModificadaMedia (4.3)0.28%—Wpchill Strong Testimonials7/6/202417/6/2026
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify…
ModificadaMedia (5.4)0.20%—Mainwp Child Reports26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1.
AnalizadaMedia (4.8)0.40%—Wpchill Strong Testimonials24/4/202417/6/2026
The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed
ModificadaMedia (4.8)0.34%—Wpchill Remove Footer Credit15/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13.
AplazadaMedia (5.4)0.20%—Catchplugins Generate Child ThemeAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0.
ModificadaMedia (5.4)0.50%—Wpchill Passster9/4/202417/6/2026
The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.2)0.27%—ChilkatAI5/4/202417/6/2026
Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.
ModificadaAlta (7.2)0.61%—Wpchill Download Monitor29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.
ModificadaAlta (7.2)2.3%💥 ExploitWensolutions WP Child Theme Generator26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
ModificadaMedia (5.3)0.54%—Wpchill Simple Restrict13/3/202417/6/2026
The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API. This makes it possible for authenticated attackers to bypass the plugin's restrictions to extract post titles and content
ModificadaMedia (5.3)0.48%—Wpchill Passster29/2/202417/6/2026
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of…
ModificadaAlta (7.5)38%💥 ExploitWpchill Download Monitor8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
ModificadaAlta (8.8)0.23%—Wpchill Strong Testimonials5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.
ModificadaAlta (8.8)0.91%—Wpchill Download Monitor20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
ModificadaAlta (8.8)0.27%—Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.
ModificadaMedia (5.4)0.43%—Wpchill CPO Shortcodes22/11/202317/6/2026
The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModificadaMedia (4.9)0.65%—Wpchill Download Monitor13/11/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
ModificadaAlta (8.8)0.25%—Sean-barton SB Child List3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions.
ModificadaMedia (6.1)0.38%—Bestdivichild Business PRO4/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.
ModificadaMedia (6.1)0.38%—Chilexpress-oficial30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <= 1.2.9 versions.
ModificadaAlta (7.5)0.66%—Mainwp Child27/6/202317/6/2026
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a…
ModificadaMedia (5.4)0.38%—Wpchill Brilliance22/6/202317/6/2026
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
Orbitaley — Vulnerabilidades