Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

2455 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.88%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to…
ModificadaCrítica (9.8)1.5%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for…
ModificadaMedia (5.3)0.68%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated…
ModificadaMedia (5.3)0.67%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a…
ModificadaAlta (8.8)0.56%—Coolplugins Process Steps Template Designer7/6/202317/6/2026
The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such…
ModificadaMedia (5.4)0.47%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and…
ModificadaCrítica (9.8)2.3%—Plugin-planet User Submitted Posts7/6/202317/6/2026
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may…
ModificadaMedia (5.4)0.43%—Accesspressthemes Frontend Post Wordpress Plugin5/6/202317/6/2026
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.
ModificadaMedia (4.8)0.37%—Booking-wp-plugin Bookly2/6/202317/6/2026
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.44%—Cincopa Video AND Media Plug-in1/6/202317/6/2026
A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file wp-media-cincopa.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to…
ModificadaAlta (8.8)0.33%—Featherplugins Feather Login Page31/5/202317/6/2026
El plugin Feather Login Page para WordPress es vulnerable a Cross-Site Request Forgery en versiones desde la 1.0.7 hasta la 1.1.1 inclusive. Esto es debido a la falta de validación nonce en la función "createTempAccountLink". Esto hace posible que atacantes no autenticados puedan crear un nuevo usuario con rol de…
ModificadaMedia (5.4)0.44%—Featherplugins Feather Login Page31/5/202317/6/2026
El plugin Feather Login Page para WordPress es vulnerable a la pérdida no autorizada de datos debido a una falta de capacidad de comprobación en la función "deleteUser" en las versiones a partir de la 1.0.7 hasta la 1.1.1 inclusive. Esto hace posible que atacantes autenticados con permisos de nivel de suscriptor y…
ModificadaAlta (8.8)0.71%—Featherplugins Feather Login Page31/5/202317/6/2026
The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
ModificadaAlta (8.8)0.27%—Metagauss Download Plugin28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.
ModificadaMedia (4.8)0.37%—Pluginops Mailchimp Subscribe Form28/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.
ModificadaAlta (8.8)0.30%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
ModificadaMedia (4.8)0.37%—Upload File Type Settings Plugin Project Upload File Type Settings Plugin26/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions.
ModificadaAlta (8.8)0.29%—Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.
ModificadaAlta (8.8)0.26%—Sigmaplugin Advanced Database Cleaner23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions.
ModificadaAlta (8.8)0.26%—Hmplugin Wordpress Books Gallery23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.
ModificadaMedia (6.1)1.2%💥 ExploitThenewsletterplugin Newsletter23/5/202317/6/2026
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.45%—Plugin Waiting18/5/202317/6/2026
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaMedia (6.1)1.7%💥 ExploitFooplugins Foogallery16/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.
ModificadaMedia (6.5)0.32%—Wpplugins Hide MY WP Ghost9/5/202317/6/2026
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For…
ModificadaMedia (6.1)0.41%—SEO Plugin BY Squirrly SEO8/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions.