Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.4%—Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+67/6/202317/6/2026
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
ModificadaMedia (4.8)0.73%—Visualcomposer Visual Composer Website Builder7/6/202317/6/2026
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
ModificadaMedia (4.8)0.64%—King-theme Page Builder Kingcomposer7/6/202317/6/2026
The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever…
ModificadaMedia (5.4)0.48%—Elementor Website Builder7/6/202317/6/2026
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user…
ModificadaAlta (8.8)1.5%—King-theme Page Builder King Composer7/6/202317/6/2026
The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to…
ModificadaAlta (8.8)1.2%—King-theme Page Builder Kingcomposer7/6/202317/6/2026
The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary…
ModificadaCrítica (9.8)1.0%—Joommasters Jmspagebuilder6/6/202317/6/2026
PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
ModificadaAlta (7.2)3.2%💥 ExploitWpdevart Pricing Table Builder5/6/202317/6/2026
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
ModificadaMedia (6.1)0.29%—Contact Form Builder BY Vcita3/6/202317/6/2026
El plugin Contact Form Builder by vcita para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 4.9.1 inclusive. Esto se debe a la falta de validación nonce en la función "ls_parse_vcita_callback". Esto hace posible que los atacantes no autenticados modifiquen la configuración del plugin e…
ModificadaMedia (5.4)0.51%—Contact Form Builder BY Vcita3/6/202317/6/2026
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as…
ModificadaMedia (4.3)0.21%—Page Builder With Image MAP BY Azexo3/6/202317/6/2026
The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_save' function. This makes it possible for unauthenticated attackers to update the post content and inject malicious…
ModificadaMedia (4.3)0.50%—Page Builder With Image MAP BY Azexo3/6/202317/6/2026
The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status.
ModificadaAlta (8.8)0.32%—Page Builder With Image MAP BY Azexo3/6/202317/6/2026
The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_add_post', 'azh_duplicate_post', 'azh_update_post' and 'azh_remove_post' functions. This makes it possible for…
ModificadaMedia (5.4)0.48%—Page Builder With Image MAP BY Azexo3/6/202317/6/2026
The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages…
ModificadaMedia (4.8)0.55%—12net Login Rebuilder30/5/202317/6/2026
The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (7.2)20%—Elementor Website Builder30/5/202317/6/2026
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
ModificadaAlta (8.8)0.26%—Crocoblock Jetformbuilder28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
ModificadaAlta (8.8)0.26%—Stylemixthemes Pearl Header Builder25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes WordPress Header Builder Plugin – Pearl plugin <= 1.3.4 versions.
ModificadaMedia (4.8)0.39%—White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions.
ModificadaAlta (7.8)0.17%—Intel DSP Builder10/5/202317/6/2026
Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.25%—Wpmart Interactive SVG Image MAP Builder10/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.
ModificadaMedia (5.4)0.44%—Topdigitaltrends Mega Addons FOR Wpbakery Page Builder8/5/202317/6/2026
The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.44%—Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder8/5/202317/6/2026
The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (4.8)0.40%—Dotcamp WP Table Builder3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions.
ModificadaAlta (8.1)0.99%—Cozmoslabs Profile Builder27/4/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function…