Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
2453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Easy Testimonials | 1/7/2023 | 17/6/2026 | The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… | |
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Locations | 1/7/2023 | 17/6/2026 | The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to update custom field meta data via a forged request… | |
| Modificada | Media (4.3) | 0.48% | — | Coolplugins Cool Timeline | 1/7/2023 | 17/6/2026 | The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a… | |
| Modificada | Alta (8.8) | 0.73% | — | Smartypantsplugins SP Project & Document Manager | 30/6/2023 | 17/6/2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for… | |
| Modificada | Media (5.4) | 0.35% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check on the ajax_store_save() function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.25% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing nonce validation on the ajax_store_save() function. This makes it possible for unauthenticated attackers to modify… | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Media (4.8) | 0.42% | — | Qumos Mojoplug Slide Panel | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions. | |
| Modificada | Alta (7.2) | 0.89% | — | Querywall Plug'n Play Firewall Project Querywall Plug'n Play Firewall | 19/6/2023 | 17/6/2026 | The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.37% | — | Aviplugins WP Register Profile With Shortcode | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Galleryplugins Video Contest | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Media (4.3) | 0.41% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,… | |
| Modificada | Media (4.3) | 0.29% | — | Wickedplugins Wicked Folders | 9/6/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Alta (8.8) | 2.2% | — | Adsanityplugin AdsanityXEN | 7/6/2023 | 17/6/2026 | El plugin AdSanity para WordPress es vulnerable a la subida de archivos arbitrarios debido a la falta de validación del tipo de archivo en la función "ajax_upload" en las versiones hasta la 1.8.1 inclusive. Esto hace posible que atacantes autenticados con privilegios de nivel "Contributor+" carguen archivos… | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Valvepress Wordpress Automatic Plugin | 7/6/2023 | 17/6/2026 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a… | |
| Modificada | Media (4.3) | 0.66% | — | Pluginmirror WP Quick Frontend Editor | 7/6/2023 | 17/6/2026 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to… | |
| Modificada | Media (5.3) | 0.80% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This… | |
| Modificada | Alta (8.8) | 1.9% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin… | |
| Modificada | Media (6.1) | 0.76% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.3) | 0.88% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for… |