Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

157 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.33%—Cusrev Customer Reviews FOR Woocommerce2/1/202517/6/2026
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through <= 5.36.0.
AplazadaAlta (7.1)0.44%—Revidev Revi-io-customer-and-product-reviewsAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revidev Revi.io revi-io-customer-and-product-reviews allows Reflected XSS.This issue affects Revi.io: from n/a through <= 5.7.3.
AplazadaMedia (5.3)0.50%—Geminilabs Site ReviewsAI9/12/202417/6/2026
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through <= 6.10.2.
AplazadaMedia (5.3)0.50%—Stamped.io Product Reviews & UGC FOR WoocommerceAI9/12/202417/6/2026
Missing Authorization vulnerability in Stamped.io Stamped.io Product Reviews & UGC for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stamped.io Product Reviews & UGC for WooCommerce: from n/a through 2.3.2.
AplazadaMedia (4.3)0.40%—Geminilabs Site ReviewsAI9/12/202417/6/2026
Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.5.0.
AplazadaMedia (5.4)0.52%—Noah Hearle Reviews AND Rating Google MY BusinessAI9/12/202417/6/2026
Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14.
AnalizadaMedia (4.3)0.28%—Cusrev Customer Reviews FOR Woocommerce16/11/202417/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import…
ModificadaMedia (5.4)0.32%—Shopitpress SIP Reviews Shortcode FOR Woocommerce31/10/202417/6/2026
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This…
ModificadaMedia (6.5)0.49%—Shopitpress SIP Reviews Shortcode FOR Woocommerce31/10/202417/6/2026
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaMedia (5.4)0.31%—Codesupply Absolute Reviews27/9/202417/6/2026
The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
AnalizadaCrítica (9.8)1.6%—Villatheme Woocommerce Photo Reviews11/9/202417/6/2026
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it…
AnalizadaMedia (4.3)0.23%—Smashballoon Reviews Feed27/8/202417/6/2026
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it…
AnalizadaMedia (4.3)0.40%—Smashballoon Reviews Feed27/8/202417/6/2026
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all versions up to, and including, 1.1.2. This makes it possible for…
AplazadaMedia (6.5)0.31%—Reviews.co.uk Reviews.ioAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Reviews.Co.Uk REVIEWS.Io allows Stored XSS.This issue affects REVIEWS.Io: from n/a through 1.2.7.
AplazadaMedia (4.3)0.28%—Saleswonder GET Better Reviews FOR WoocommerceAI12/7/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias Get Better Reviews for WooCommerce more-better-reviews-for-woocommerce.This issue affects Get Better Reviews for WooCommerce: from n/a through <= 4.0.6.
AplazadaMedia (5.3)0.37%—Saleswonder Builder FOR Woocommerce Reviews Shortcodes ReviewshortAI11/6/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.5.
AnalizadaCrítica (9.1)0.56%—Geminilabs Site Reviews29/5/202417/6/2026
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
AplazadaMedia (6.4)0.38%—Reviews AND Rating Google ReviewsAI25/5/202417/6/2026
The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
AplazadaMedia (6.5)0.37%💥 PoCKemory Grubb Recencio-book-reviewsAI29/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews recencio-book-reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through <= 1.66.0.
AplazadaMedia (4.3)0.34%—Implecode Reviews PlusAI26/4/202417/6/2026
Missing Authorization vulnerability in impleCode Reviews Plus.This issue affects Reviews Plus: from n/a through 1.3.4.
ModificadaMedia (6.1)0.37%—Cusrev Customer Reviews FOR Woocommerce19/4/202417/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
ModificadaMedia (4.3)0.45%—Cusrev Customer Reviews FOR Woocommerce16/4/202417/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
ModificadaMedia (4.3)0.43%—Cusrev Customer Reviews FOR Woocommerce16/4/202417/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send…
AnalizadaMedia (5.4)0.50%—Gowebsolutions WP Customer Reviews15/4/202417/6/2026
The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
AplazadaAlta (8)0.53%—Trustindex Widgets FOR Google ReviewsAI26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.
Orbitaley — Vulnerabilidades