Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.18% | — | Aftabhusain Category AND Taxonomy Meta Fields | 22/10/2024 | 17/6/2026 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the 'wpaft_option_page' function. This makes it possible for unauthenticated attackers to add and delete taxonomy meta,… | |
| Aplazada | Media (5.3) | 0.53% | — | Secure Custom FieldsAIAdvancedcustomfields Advanced Custom FieldsAI | 17/10/2024 | 17/6/2026 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF,… | |
| Analizada | Media (4.3) | 0.40% | — | Codepeople Calculated Fields Form | 17/10/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the… | |
| Aplazada | Media (6.5) | 0.43% | — | ACF Quick Edit FieldsAI | 16/10/2024 | 17/6/2026 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above. | |
| Analizada | Media (5.4) | 0.38% | — | Webhammer WP Custom Fields Search | 19/9/2024 | 17/6/2026 | The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and including, 1.2.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.1) | 0.42% | — | Wpengine Advanced Custom Fields | 4/9/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed… | |
| Aplazada | Media (4.3) | 0.22% | — | Conditional Fields FOR Contact Form 7AI | 20/7/2024 | 17/6/2026 | The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's… | |
| Aplazada | Media (4.3) | 0.20% | — | Just Custom FieldsAI | 9/7/2024 | 17/6/2026 | The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on several AJAX function. This makes it possible for unauthenticated attackers to invoke this functionality intended for admin users… | |
| Aplazada | Media (4.3) | 0.30% | — | Just Custom FieldsAI | 9/7/2024 | 17/6/2026 | The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this… | |
| Modificada | Media (6.5) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 20/6/2024 | 17/6/2026 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access | |
| Modificada | Media (5.3) | 0.33% | — | Themeisle Product Addons & Fields FOR Woocommerce | 10/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20. | |
| Aplazada | Crítica (9.9) | 0.59% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Aplazada | Alta (8.5) | 0.43% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Modificada | Crítica (9.8) | 0.36% | — | Softlabbd Upload Fields FOR Wpforms | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2. | |
| Modificada | Alta (8.8) | 0.35% | — | Websupporter Filter Custom Fields & Taxonomies Light Project Websupporter Filter Custom Fields & Taxonomies Light | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpdesk Flexible Checkout Fields | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | |
| Analizada | Media (4.3) | 0.31% | — | Codepeople Calculated Fields Form | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120. | |
| Aplazada | Media (5.3) | 0.54% | — | Fmeaddons Conditional Checkout Fields FOR WoocommerceAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3. | |
| Aplazada | Media (4.3) | 0.44% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. | |
| Aplazada | Media (6.1) | 0.18% | — | Delete Custom FieldsAI | 2/5/2024 | 17/6/2026 | The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to missing or incorrect nonce validation on the ajax_delete_field() function. This makes it possible for unauthenticated attackers to delete arbitrary post meta data via a… | |
| Aplazada | Alta (7.5) | 0.99% | — | Fmemodules CustomfieldsAI | 30/4/2024 | 17/6/2026 | Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php | |
| Modificada | Crítica (9.8) | 1.4% | — | Themeisle Product Addons & Fields FOR Woocommerce | 26/4/2024 | 17/6/2026 | The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Media (4.3) | 0.20% | — | Tychesoftwares Product Input Fields FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0. | |
| Aplazada | Media (6.4) | 0.43% | — | Metabox Custom Post Types Custom Fields MoreAI | 9/4/2024 | 17/6/2026 | The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping on user supplied post meta values. This makes it possible… | |
| Aplazada | Alta (8.5) | 0.55% | — | Filter Custom Fields & Taxonomies LightAI | 31/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. |