Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.31% | — | 5starplugins Pretty Simple Popup BuilderAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugins Pretty Simple Popup Builder pretty-simple-popup-builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.3) | 0.34% | — | Popup Mailchimp Getresponse AND Activecampaign IntergrationsAI | 7/1/2025 | 17/6/2026 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'upc_delete_db_data' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to delete the… | |
| Aplazada | Alta (7.5) | 1.00% | 💥 PoC | PopupAI | 7/1/2025 | 17/6/2026 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (5.4) | 0.41% | — | Mare.io Popup Surveys AND PollsAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through <= 1.36. | |
| Aplazada | Media (6.4) | 0.37% | — | Smart Popup BlasterAI | 14/12/2024 | 17/6/2026 | The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.67% | — | Supsystic Popup | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19. | |
| Modificada | Baja (3.5) | 0.42% | — | Code-atlantic Popup Maker | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1. | |
| Analizada | Media (5.4) | 0.31% | — | Code-atlantic Popup Maker | 12/12/2024 | 17/6/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (4.8) | 0.35% | — | Sygnoos Popup Builder | 12/12/2024 | 17/6/2026 | The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.45% | — | Catch PopupAI | 12/12/2024 | 17/6/2026 | The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortcode in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.57% | — | Supsystic Popup | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19. | |
| Aplazada | Media (6.4) | 0.26% | — | Smart Popup BlasterAI | 6/12/2024 | 17/6/2026 | The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.24% | — | Garrettgrimm Simple PopupAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Popup simple-popup-plugin allows DOM-Based XSS.This issue affects Simple Popup: from n/a through <= 4.6. | |
| Aplazada | Alta (7.1) | 0.18% | — | Wp-buy WP Popup Window MakerAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Popup Window Maker easy-popup-lightbox-maker allows Stored XSS.This issue affects WP Popup Window Maker: from n/a through <= 2.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Hussam Hussien Popup ImageAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image popup-image allows Stored XSS.This issue affects Popup Image: from n/a through <= 1.0.1. | |
| Analizada | Media (6.4) | 0.37% | — | I13websolution Email Subscription Popup | 19/11/2024 | 17/6/2026 | The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7.3) | 0.60% | — | Wpbean WPB Popup FOR Contact Form 7 | 19/11/2024 | 17/6/2026 | The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form AJAX action in all versions up to, and including, 1.7.5. This is due to the software allowing users to execute an action… | |
| Modificada | Crítica (9.1) | 1.1% | — | Supsystic Popup | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29. | |
| Aplazada | Media (5.3) | 0.39% | — | Popup BOXAI | 16/11/2024 | 17/6/2026 | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | Medmatech Matix Popup BuilderAI | 14/11/2024 | 17/6/2026 | Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.1) | 0.46% | — | Ajax Login AND Registration Modal Popup Inline FormAI | 13/11/2024 | 17/6/2026 | The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.24. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 0.41% | — | Code-atlantic Popup Maker | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Popup BOX Team Popup BOXAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Popup Box Team Popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup box: from n/a through 4.5.1. | |
| Aplazada | Alta (7.5) | 0.52% | — | Wpopin TOP BAR PopupsAI | 16/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows PHP Local File Inclusion.This issue affects Top Bar – PopUps – by WPOptin: from n/a through <= 2.0.1. | |
| Analizada | Crítica (9.8) | 52% | 💥 Exploit | Themehunk WP Popup Builder | 16/10/2024 | 17/6/2026 | The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not… |