Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
2455 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.88% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for… | |
| Modificada | Media (5.3) | 0.68% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated… | |
| Modificada | Media (5.3) | 0.67% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a… | |
| Modificada | Alta (8.8) | 0.56% | — | Coolplugins Process Steps Template Designer | 7/6/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such… | |
| Modificada | Media (5.4) | 0.47% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and… | |
| Modificada | Crítica (9.8) | 2.3% | — | Plugin-planet User Submitted Posts | 7/6/2023 | 17/6/2026 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may… | |
| Modificada | Media (5.4) | 0.43% | — | Accesspressthemes Frontend Post Wordpress Plugin | 5/6/2023 | 17/6/2026 | The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain. | |
| Modificada | Media (4.8) | 0.37% | — | Booking-wp-plugin Bookly | 2/6/2023 | 17/6/2026 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages… | |
| Modificada | Alta (8.8) | 0.44% | — | Cincopa Video AND Media Plug-in | 1/6/2023 | 17/6/2026 | A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file wp-media-cincopa.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to… | |
| Modificada | Alta (8.8) | 0.33% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | El plugin Feather Login Page para WordPress es vulnerable a Cross-Site Request Forgery en versiones desde la 1.0.7 hasta la 1.1.1 inclusive. Esto es debido a la falta de validación nonce en la función "createTempAccountLink". Esto hace posible que atacantes no autenticados puedan crear un nuevo usuario con rol de… | |
| Modificada | Media (5.4) | 0.44% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | El plugin Feather Login Page para WordPress es vulnerable a la pérdida no autorizada de datos debido a una falta de capacidad de comprobación en la función "deleteUser" en las versiones a partir de la 1.0.7 hasta la 1.1.1 inclusive. Esto hace posible que atacantes autenticados con permisos de nivel de suscriptor y… | |
| Modificada | Alta (8.8) | 0.71% | — | Featherplugins Feather Login Page | 31/5/2023 | 17/6/2026 | The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Alta (8.8) | 0.27% | — | Metagauss Download Plugin | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Pluginops Mailchimp Subscribe Form | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Upload File Type Settings Plugin Project Upload File Type Settings Plugin | 26/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Sigmaplugin Advanced Database Cleaner | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Hmplugin Wordpress Books Gallery | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Thenewsletterplugin Newsletter | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.45% | — | Plugin Waiting | 18/5/2023 | 17/6/2026 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Fooplugins Foogallery | 16/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. | |
| Modificada | Media (6.5) | 0.32% | — | Wpplugins Hide MY WP Ghost | 9/5/2023 | 17/6/2026 | The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For… | |
| Modificada | Media (6.1) | 0.41% | — | SEO Plugin BY Squirrly SEO | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions. |