Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.26% | — | Impress FOR IDX BrokerAI | 10/9/2026 | 10/9/2026 | Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Impress FOR IDX BrokerAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. | |
| Analizada | Media (6.9) | 0.15% | — | Google Common Expression Language | 9/9/2026 | 23/9/2026 | A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. | |
| Aplazada | Alta (7.2) | 0.64% | — | Publishpress CapabilitiesAI | 9/9/2026 | 11/9/2026 | The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15… | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 9/9/2026 | 9/9/2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Media (6.4) | 0.20% | — | Thimpress LearnpressAI | 8/9/2026 | 9/9/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.7) | 0.20% | — | Asus Control Center Express AgentAI | 8/9/2026 | 28/9/2026 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS… | |
| Aplazada | Alta (7.5) | 0.34% | — | Hivepress AuthenticationAI | 6/9/2026 | 8/9/2026 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to… | |
| Aplazada | Media (5.3) | 0.30% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows… | |
| Aplazada | Baja (2.7) | 0.28% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly… | |
| Aplazada | Baja (2.7) | 0.32% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role. | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Media (5.1) | 0.24% | — | Thimpress LearnpressAI | 3/9/2026 | 8/9/2026 | LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the… | |
| Aplazada | Media (5.3) | 0.29% | — | Thimpress LearnpressAI | 3/9/2026 | 8/9/2026 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply… | |
| Aplazada | Media (6.5) | 0.33% | — | Mountdev AI MCP Connector FOR WordpressAI | 3/9/2026 | 4/9/2026 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5. | |
| Aplazada | Media (5.4) | 0.21% | — | SeopressAI | 3/9/2026 | 5/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. | |
| Aplazada | Alta (8.2) | 0.39% | — | Wpcompress WP CompressAI | 3/9/2026 | 3/9/2026 | Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. | |
| Pendiente de análisis | Alta (7.8) | 1.0% | — | RpmuncompressAI | 2/9/2026 | 3/9/2026 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings.… | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 2/9/2026 | 3/9/2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Baja (3.5) | 0.17% | — | Icegram ExpressAI | 2/9/2026 | 3/9/2026 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Alta (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 2/9/2026 | 3/9/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Aplazada | Media (5.3) | 0.31% | — | Publishpress PermissionsAI | 2/9/2026 | 2/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | GamipressAI | 2/9/2026 | 3/9/2026 | The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (4.9) | 0.44% | — | Thimpress LearnpressAI | 1/9/2026 | 1/9/2026 | The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the… |