Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.56%—Aftabhusain Enable Shortcodes Inside Widgets,comments AND Experts30/10/202417/6/2026
The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…
AnalizadaMedia (6.1)0.41%—Markjaquith Subscribe TO Comments30/10/202417/6/2026
The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
AplazadaCrítica (10)0.51%—Jclay06 Feed Comments NumberAI16/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through <= 0.2.1.
AplazadaMedia (6.5)1.1%💥 PoCComments Import ExportAI11/10/202417/6/2026
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the…
AnalizadaMedia (5.9)0.21%—Yasirwazir Send Email Only ON Reply TO MY Comment30/7/202417/6/2026
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaMedia (6.1)0.40%—Yasirwazir Send Email Only ON Reply TO MY Comment30/7/202417/6/2026
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (5.3)0.45%—ONE Click Close CommentsAI27/7/202417/6/2026
The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
AplazadaAlta (7.1)0.23%—Wpjohnny Comment Reply EmailAI12/7/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Comment Reply Email: from n/a through 1.3.
AplazadaMedia (4.3)0.40%—Comment Images ReloadedAI9/7/202417/6/2026
The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary…
AplazadaMedia (4.3)0.40%—Wphappycoders Comments Like DislikeAI17/5/202417/6/2026
Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.
AplazadaMedia (5.9)0.44%—Talspotim Comments EvolvedAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments Evolved for WordPress allows Stored XSS.This issue affects Comments Evolved for WordPress: from n/a through 1.6.3.
ModificadaMedia (5.4)0.40%—Utopique Better Comments24/4/202417/6/2026
The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.
AnalizadaMedia (5.4)0.40%—Utopique Better Comments24/4/202417/6/2026
The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (4.3)0.34%—Genialsouls WP Social CommentsAI18/4/202417/6/2026
Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.
AplazadaMedia (5.3)0.36%—Prasidhdamalla Honeypot FOR WP CommentAI17/4/202417/6/2026
Missing Authorization vulnerability in Prasidhda Malla Honeypot for WP Comment.This issue affects Honeypot for WP Comment: from n/a through 2.2.3.
AplazadaAlta (7.6)0.52%—Wpzest Disable CommentsAI15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51.
AplazadaMedia (4.3)0.23%—Webtoffee Wordpress Comments Import ExportAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5.
ModificadaAlta (7.5)0.51%—Wpkube Subscribe TO Comments Reloaded10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
AplazadaMedia (6.5)0.33%—Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8.
ModificadaMedia (5.4)0.34%—Heateor Fancy Comments27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.
AnalizadaCrítica (9.8)0.83%—Sunnytoo Product Comments14/3/202417/6/2026
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.
AnalizadaMedia (4.3)0.30%—Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT13/3/202411/8/2026
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a…
AnalizadaMedia (4.3)0.53%—Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT13/3/202411/8/2026
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to…
ModificadaMedia (6.1)0.33%—Prasidhdamalla Honeypot FOR WP Comment12/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Honeypot for WP Comment allows Reflected XSS.This issue affects Honeypot for WP Comment: from n/a through 2.2.3.
ModificadaMedia (5.3)0.61%—OBG ARK Wysiwyg Comment Editor16/1/202417/6/2026
The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section