Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.35% | — | Webappick CTX FeedAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WebAppick CTX Feed webappick-product-feed-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CTX Feed: from n/a through <= 6.6.18. | |
| Aplazada | Media (5.9) | 0.44% | — | Feeds FOR Youtube PROAI | 17/1/2026 | 17/6/2026 | The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp_submit' AJAX action. This is due to insufficient sanitization of user-supplied data and the use of that data in a file operation. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.20% | — | Fahadmahmood RSS Feed WidgetAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RSS Feed Widget: from n/a through <= 3.0.2. | |
| Aplazada | Media (5.3) | 0.21% | — | Quadlayers Wp-tiktok-feedAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in quadlayers QuadLayers TikTok Feed wp-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QuadLayers TikTok Feed: from n/a through <= 4.6.5. | |
| Aplazada | Media (5.3) | 0.27% | — | Trustindex Widgets FOR Social Photo FeedAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widgets for Social Photo Feed: from n/a through <= 1.8. | |
| Aplazada | Alta (7.6) | 0.47% | — | Syedbalkhi User FeedbackAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Syedbalkhi Feeds FOR YoutubeAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Feeds for YouTube: from n/a through <= 2.4.0. | |
| Aplazada | Media (6.4) | 0.22% | — | AI FeedsAI | 12/12/2025 | 17/6/2026 | The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.25% | — | Flow-flow Flow Flow Social Feed StreamAI | 12/12/2025 | 17/6/2026 | The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX action in versions 3.0.0 to 4.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin… | |
| Aplazada | Media (5.8) | 0.26% | — | Feedzy RSS AggregatorAI | 11/12/2025 | 30/9/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web… | |
| Aplazada | Media (5.9) | 0.21% | — | Winwar WP Ebay Product FeedsAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Stored XSS.This issue affects WP eBay Product Feeds: from n/a through <= 3.4.9. | |
| Aplazada | Media (5.9) | 0.22% | — | Etruel Wpematico RSS Feed FetcherAI | 9/12/2025 | 17/6/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.4) | 0.23% | — | Social Feed Gallery PortfolioAI | 6/12/2025 | 17/6/2026 | The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.90% | 💥 Exploit | Feedback Modal FOR WebsiteAI | 5/12/2025 | 17/6/2026 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the… | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | AI FeedsAI | 25/11/2025 | 17/6/2026 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.0.11. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the… | |
| Aplazada | Media (5.3) | 0.21% | — | Bplugins Tiktok FeedAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tiktok Feed: from n/a through <= 1.0.23. | |
| Aplazada | Media (4.3) | 0.20% | — | Webtoffee Product Feed FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1. | |
| Aplazada | Media (6.4) | 0.18% | — | Devbuddy Twitter FeedAI | 11/11/2025 | 17/6/2026 | The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.24% | — | Etruel Wpematico RSS Feed FetcherAI | 5/11/2025 | 17/6/2026 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (5.3) | 0.30% | — | Social Feed GalleryAI | 25/10/2025 | 17/6/2026 | The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate Instagram profile and media… | |
| Aplazada | Media (5.3) | 0.26% | — | User FeedbackAI | 25/10/2025 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for… | |
| Aplazada | Media (5) | 0.29% | — | Feedzy RSS AggregatorAI | 23/10/2025 | 30/9/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bplugins Voice FeedbackAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.24% | — | Smashballoon Social Post FeedAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Smash Balloon Social Post Feed custom-facebook-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smash Balloon Social Post Feed: from n/a through <= 4.3.2. | |
| Aplazada | Media (4.3) | 0.13% | — | Sync FeedlyAI | 27/9/2025 | 30/9/2026 | The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the crsf_cron_job_func function. This makes it possible for unauthenticated attackers to trigger content synchronization from Feedly,… |