Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
1061 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.6) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 30/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.7.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Blueglass Jobs FOR WordpressAI | 24/12/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2.8.1. | |
| Aplazada | Alta (7.2) | 0.23% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 21/12/2025 | 28/9/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.5) | 0.21% | — | Getresponse Email Marketing FOR WordpressAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Getresponse Email Marketing FOR WordpressAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Retrieve Embedded Sensitive Data.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3. | |
| Aplazada | Crítica (9.9) | 0.32% | — | Redefiningtheweb Wordpress Contact Form 7 PDF Google Sheet & DatabaseAI | 18/12/2025 | 5/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0. | |
| Aplazada | Crítica (9.8) | 0.41% | — | URL Shortener Plugin FOR WordpressAI | 13/12/2025 | 30/9/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.23% | — | Wpik Wordpress Basic Ajax FormAI | 12/12/2025 | 17/6/2026 | The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Media (6.5) | 0.20% | — | Vibethemes Wordpress Learning Management System | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows DOM-Based XSS.This issue affects WPLMS: from n/a through <= 1.9.9.5.4. | |
| Aplazada | Media (6.5) | 0.49% | — | LQD AI Engine FOR WordpressAI | 25/11/2025 | 17/6/2026 | The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'lqdai_update_post' AJAX endpoint and the use of file_get_contents() with… | |
| Aplazada | Alta (7.1) | 0.40% | — | Wordpress EcommerceAI | 24/11/2025 | 1/10/2026 | The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (6.4) | 0.18% | — | Brighttalk Wordpress ShortcodeAI | 21/11/2025 | 17/6/2026 | The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the brighttalk-time shortcode in all versions up to, and including, 2.4.0. This is due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Aplazada | Media (5.3) | 0.20% | — | Slimndap Theater FOR WordpressAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (6.4) | 0.22% | — | Wordpress Content FlipperAI | 13/11/2025 | 17/6/2026 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.52% | — | Wordpress LMS Academy LMSAI | 8/11/2025 | 17/6/2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_courses' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.19% | — | Html Forms Simple Wordpress Forms PluginAI | 8/11/2025 | 17/6/2026 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (8.1) | 0.41% | — | Blanka Theme Developers Blanka - ONE Page Wordpress ThemeAI | 6/11/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5. | |
| Aplazada | Media (6.5) | 0.17% | — | Wordpress GutenbergAI | 31/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2. | |
| Aplazada | Alta (8.8) | 0.70% | — | Wordpress User Extra FieldsAI | 31/10/2025 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Media (6.5) | 0.17% | — | Builderall Builder FOR WordpressAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1. | |
| Aplazada | Media (5.4) | 0.27% | — | Microsoft Azure Storage FOR WordpressAI | 24/10/2025 | 17/6/2026 | The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and including, 4.5.1. This is due to missing capability checks on the 'azure-storage-media-replace' AJAX action. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.3) | 0.27% | — | URL Shortener Plugin FOR WordpressAI | 24/10/2025 | 17/6/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.1) | 0.24% | — | Themewarriors Whatsapp Chat FOR Wordpress AND WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through <= 1.2.1. | |
| Modificada | Alta (7.1) | 0.25% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows Reflected XSS.This issue affects WPLMS: from n/a through <= 1.9.9.8. |