Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.64% | — | Judge Product Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.51% | — | Trustindex Widgets FOR Google Reviews | 30/1/2023 | 17/6/2026 | The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (4.3) | 0.53% | — | Richplugins Plugin FOR Google Reviews | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress. | |
| Modificada | Alta (7.5) | 0.91% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress | |
| Modificada | Alta (8.8) | 0.38% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | |
| Modificada | Alta (8.8) | 1.0% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | |
| Modificada | Media (6.5) | 0.43% | — | Yotpo Reviews FOR Woocommerce Project Yotpo Reviews FOR Woocommerce | 22/8/2022 | 17/6/2026 | The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (5.3) | 0.85% | — | Wbcomdesigns Buddypress Group Reviews | 18/7/2022 | 17/6/2026 | The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for… | |
| Modificada | Media (4.8) | 0.59% | — | Wpreviewslider WP Zillow Review Slider | 20/6/2022 | 17/6/2026 | The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite) | |
| Modificada | Media (4.8) | 0.75% | — | Google Places Reviews Project Google Places Reviews | 13/6/2022 | 17/6/2026 | The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (4.8) | 0.56% | — | Etoilewebdesign Ultimate Reviews | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15). | |
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 3/1/2022 | 17/6/2026 | The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin | |
| Modificada | Media (6.5) | 1.5% | — | Implecode Reviews Plus | 23/11/2021 | 17/6/2026 | The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page | |
| Modificada | Media (5.4) | 0.62% | — | Geminilabs Site Reviews | 6/9/2021 | 17/6/2026 | The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed | |
| Modificada | Alta (8.8) | 1.6% | — | Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews | 2/8/2021 | 17/6/2026 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue. | |
| Modificada | Media (4.8) | 0.62% | — | Gowebsolutions WP Customer Reviews | 24/5/2021 | 17/6/2026 | The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled | |
| Modificada | Media (6.1) | 1.1% | — | Gowebsolutions WP Customer Reviews | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Reviews | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Crítica (9.8) | 1.4% | — | Reviews Module Project Reviews Module | 26/8/2019 | 17/6/2026 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. | |
| Modificada | Alta (8.8) | 0.68% | — | Gowebsolutions WP Customer Reviews | 21/8/2019 | 17/6/2026 | The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools. | |
| Modificada | Media (6.1) | 0.91% | — | Gowebsolutions WP Customer Reviews | 21/8/2019 | 17/6/2026 | The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools. | |
| Modificada | Media (5.4) | 0.65% | — | Consumer Reviews Script Project Consumer Reviews Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box. | |
| Modificada | Media (6.5) | 1.6% | — | Consumer Reviews Script Project Consumer Reviews Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. |