Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.55% | — | Bard ExtraAI | 21/11/2024 | 17/6/2026 | The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to import demo data. | |
| Aplazada | Media (4.3) | 0.33% | — | Themes4wp Popularis ExtraAI | 16/11/2024 | 17/6/2026 | The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Crítica (9.8) | 1.4% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Analizada | Alta (8.8) | 0.82% | — | Vanquish User Extra Fields | 13/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all versions up to, and including, 16.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to add custom fields… | |
| Analizada | Media (4.3) | 0.31% | — | Futuriowp Futurio Extra | 12/11/2024 | 17/6/2026 | The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wordpress User Extra FieldsAI | 9/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 16.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Media (4.3) | 0.30% | — | Attesa ExtraAI | 9/11/2024 | 17/6/2026 | The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 via the 'attesa-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (4.3) | 0.31% | — | Envothemes Envo Extra | 9/11/2024 | 17/6/2026 | The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (6.1) | 0.29% | — | Marianheddesheimer Extra Privacy FOR Elementor | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor extra-privacy-for-elementor allows Reflected XSS.This issue affects Extra Privacy for Elementor: from n/a through <= 0.1.3. | |
| Modificada | Media (5.4) | 0.26% | — | Futuriowp Futurio Extra | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio Extra futurio-extra.This issue affects Futurio Extra: from n/a through <= 2.0.11. | |
| Aplazada | Media (6.1) | 0.40% | — | Rednao Extra Product Options BuilderAI | 24/10/2024 | 17/6/2026 | The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (4.3) | 0.40% | — | Sinaextra Sina Extension FOR Elementor | 16/10/2024 | 17/6/2026 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render function in widgets/advanced/sina-modal-box.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract… | |
| Analizada | Media (6.9) | 0.55% | — | Codeclysm Extract | 11/10/2024 | 17/6/2026 | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to… | |
| Analizada | Media (5.4) | 0.39% | — | Averta Shortcodes AND Extra Features FOR Phlox Theme | 5/10/2024 | 17/6/2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (6.1) | 0.39% | — | Themes4wp Popularis Extra | 4/10/2024 | 17/6/2026 | The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Yaycommerce YayextraAI | 3/8/2024 | 17/6/2026 | The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Modificada | Media (5.4) | 0.31% | — | Oceanwp Ocean Extra | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.2.9. | |
| Modificada | Media (5.4) | 0.45% | — | Sinaextra Sina Extension FOR Elementor | 2/7/2024 | 17/6/2026 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘read_more_text’ parameter in all versions up to, and including, 3.5.5 due to insufficient input… | |
| Modificada | Media (5.4) | 0.39% | — | Sinaextra Sina Extension FOR Elementor | 20/6/2024 | 17/6/2026 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.5.4 due to insufficient input sanitization and… | |
| Modificada | Media (5.4) | 0.31% | — | Futuriowp Futurio Extra | 11/6/2024 | 17/6/2026 | The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.31% | — | Oceanwp Ocean ExtraAI | 11/6/2024 | 17/6/2026 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access… | |
| Modificada | Alta (8.8) | 0.32% | — | Actpro Extra Product Options FOR Woocommerce | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6. | |
| Modificada | Media (5.4) | 0.24% | — | Sinaextra Sina Extension FOR Elementor | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.3. | |
| Modificada | Media (5.4) | 0.32% | — | Envothemes Envo Extra | 7/6/2024 | 17/6/2026 | The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Alta (8.8) | 0.57% | — | Sinaextra Sina Extension FOR Elementor | 4/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension for Elementor allows PHP Local File Inclusion.This issue affects Sina Extension for Elementor: from n/a through 3.5.1. |