Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)90%💥 ExploitWpexperts Post Smtp11/1/202417/6/2026
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible…
ModificadaMedia (6.1)0.40%—Wpexperts Post Smtp3/1/202417/6/2026
The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (5.4)0.94%—Wpexperts Post Smtp3/1/202417/6/2026
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaMedia (6.1)0.44%—Wpexperts Post Smtp3/1/202417/6/2026
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible…
ModificadaAlta (8.8)0.23%—Wpexperts NEW User Approve29/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.
ModificadaMedia (4.8)0.39%—Wpexperts Rocket Maintenance Mode & Coming Soon Page14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3.
ModificadaMedia (5.4)0.39%—Wpexperts Mycred30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin allows Stored XSS.This issue affects myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin: from n/a through 2.6.1.
ModificadaAlta (7.2)0.70%—Wpexperts License Manager FOR Woocommerce30/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10.
ModificadaMedia (6.1)0.51%—Wpexperts Post Smtp27/11/202317/6/2026
The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.
ModificadaAlta (8.8)0.28%—Wpexperts Email Templates Customizer AND Designer7/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2.
ModificadaMedia (5.4)0.40%—Henryholtgeerts PDF Block25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Henryholtgeerts PDF Block plugin <= 1.1.0 versions.
ModificadaMedia (5.4)0.46%—Wpexperts User Avatar-reloaded16/10/202317/6/2026
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
ModificadaMedia (6.1)0.38%—Wp-experts Wp-categories-widget4/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP-EXPERTS.IN TEAM WP Categories Widget plugin <= 2.2 versions.
AnalizadaAlta (7.5)0.84%—Wpexperts ALL IN ONE Login21/8/202317/6/2026
The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.
ModificadaMedia (5.4)0.36%—Thechrisroberts Tippy17/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.
ModificadaAlta (8.8)0.39%—Wpexperts Post Smtp17/7/202317/6/2026
The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled…
ModificadaAlta (8.8)0.25%—Wpexperts Mycred17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.
ModificadaAlta (8.8)0.25%—Wpexperts WP PDF Generator17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions.
ModificadaMedia (4.3)0.54%—Wpexperts Post Smtp12/7/202317/6/2026
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request…
ModificadaMedia (6.1)0.50%—Wpexperts Post Smtp12/7/202317/6/2026
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever…
ModificadaMedia (6.1)0.73%💥 ExploitWp-experts Protect WP Admin4/7/202317/6/2026
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
ModificadaMedia (4.8)0.40%—Wpexperts Password Protected23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions.
ModificadaAlta (8.8)1.2%—Wpexperts Email Templates7/6/202317/6/2026
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators.
ModificadaMedia (5.4)0.44%—Wpexperts WP Multi Store Locator5/6/202317/6/2026
The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.36%—Digitalalertsystems Dasdec II FirmwareDigitalalertsystems One-net SE FirmwareDigitalalertsystems Dasdec I FirmwareDigitalalertsystems One-net Firmware+11/12/202217/6/2026
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
Orbitaley — Vulnerabilidades