Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
3372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.38% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Crítica (9.8) | 0.63% | — | PressengineAI | 17/9/2026 | 18/9/2026 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators. | |
| Aplazada | Baja (3.7) | 0.28% | — | Thimpress LearnpressAI | 17/9/2026 | 18/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling. | |
| Aplazada | Alta (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 17/9/2026 | 18/9/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Aplazada | Media (5.3) | 0.27% | — | LoginwordpressAIWwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out… | |
| Aplazada | Media (5.3) | 0.34% | — | Thimpress LearnpressAI | 16/9/2026 | 17/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones. | |
| Aplazada | Baja (3.7) | 0.31% | — | Thimpress LearnpressAI | 16/9/2026 | 17/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated attackers who can determine its identifier to download customer names, purchases, amounts and guest email addresses. | |
| Aplazada | Media (5.3) | 0.34% | — | Thimpress LearnpressAI | 16/9/2026 | 17/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against the course they are enrolled on, and to recover their email addresses through the… | |
| Aplazada | Media (5.3) | 0.34% | — | Thimpress LearnpressAI | 16/9/2026 | 17/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the… | |
| Aplazada | Alta (7.1) | 0.28% | — | Thimpress LearnpressAI | 16/9/2026 | 17/9/2026 | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who opens a crafted link, including a logged in administrator. Only sites running a… | |
| Aplazada | Alta (7.1) | 0.34% | — | Multivendorx Wordpress PluginAI | 16/9/2026 | 17/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it. | |
| Aplazada | Alta (7.2) | 0.40% | — | Motopress Hotel BookingAI | 15/9/2026 | 16/9/2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.7) | 0.54% | — | Wordpress Design Scuole ItaliaAI | 15/9/2026 | 18/9/2026 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process. | |
| Aplazada | Media (5.5) | 0.43% | — | Zyx0814 FilepressAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql injection. The attack can be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.4) | 0.24% | — | Publishpress AuthorsAI | 15/9/2026 | 15/9/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output… | |
| Pendiente de análisis | Media (5.3) | 0.53% | — | Expressjs MulterAI | 14/9/2026 | 16/9/2026 | multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A… | |
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… | |
| Aplazada | Media (5.3) | 0.31% | — | BbpressAI | 11/9/2026 | 11/9/2026 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | 10up ElasticpressAI | 11/9/2026 | 11/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4. | |
| Aplazada | Media (6.5) | 0.23% | — | GamipressAI | 11/9/2026 | 11/9/2026 | The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The value is passed only through $wpdb->esc_like() and interpolated directly into a… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | CompressionAINodejs Node.jsAIExpressjs ExpressAI | 11/9/2026 | 16/9/2026 | compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote… | |
| Aplazada | Media (4.3) | 0.19% | — | BuddypressAI | 11/9/2026 | 11/9/2026 | The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Alta (7.2) | 0.46% | — | Multivendorx Wordpress PluginAI | 11/9/2026 | 11/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. | |
| Aplazada | Baja (3.5) | 0.14% | — | Translate Wordpress With GtranslateAI | 11/9/2026 | 11/9/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. |