Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.33%—Slidervilla Testimonial Slider8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
AnalizadaMedia (4.8)0.46%—Themepoints Super Testimonials28/10/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
ModificadaMedia (5.4)0.51%—Gsplugins GS Testimonial Slider23/9/202217/6/2026
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.
ModificadaMedia (5.4)0.59%—Wpshopmart Testimonial Builder22/8/202217/6/2026
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.1 at WordPress.
ModificadaMedia (4.8)0.57%—Gsplugins GS Testimonial Slider28/7/202217/6/2026
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.5 at WordPress.
ModificadaMedia (5.4)0.56%—Testimonials Project Testimonials22/7/202217/6/2026
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.
ModificadaMedia (4.8)0.74%—Vertistudio Image Optimization & Lazy Load BY Optimole11/4/202217/6/2026
The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload background images for selectors" settings, which could allow high privilege users such as admin to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.4)0.57%—Web-settler Testimonial Slider4/4/202217/6/2026
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.
ModificadaMedia (6.1)0.87%—Accesspressthemes AP Custom Testimonial28/2/202217/6/2026
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
ModificadaAlta (7.2)1.5%—Accesspressthemes AP Custom Testimonial28/2/202217/6/2026
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
ModificadaMedia (6.1)0.62%—Notimoo Project Notimoo25/2/202217/6/2026
A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaAlta (7.2)1.1%—Optimocha Speed Booster Pack3/1/202217/6/2026
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection
ModificadaMedia (4.8)0.68%—Wpshopmart Testimonial Builder17/11/202117/6/2026
The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.2)1.5%—Easy Testimonial Manager Project Easy Testimonial Manager6/9/202117/6/2026
An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
ModificadaAlta (8.8)1.6%—Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews2/8/202117/6/2026
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
ModificadaAlta (7.2)1.7%—Optimocha Speed Booster Pack2/8/202117/6/2026
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
ModificadaMedia (5.4)0.69%—Testimonial Rotator Project Testimonial Rotator5/4/202117/6/2026
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
ModificadaMedia (5.4)0.82%—Axelerant Testimonials Widget18/3/202117/6/2026
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
ModificadaMedia (5.4)0.72%—Testimonial Rotator Project Testimonial Rotator16/10/202017/6/2026
Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.
ModificadaMedia (5.4)0.89%—Goldplugins Easy Testimonials22/6/202017/6/2026
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
ModificadaMedia (6.1)1.9%—Wpchill Strong Testimonials3/2/202017/6/2026
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
ModificadaMedia (6.1)3.7%💥 ExploitHitmyserver HMS Testimonials30/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format…
ModificadaMedia (6.5)0.67%—Slidervilla Testimonial Slider26/9/201917/6/2026
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Testimonials21/8/201917/6/2026
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
Orbitaley — Vulnerabilidades