Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.41% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Etoilewebdesign Ultimate Reviews | 7/6/2023 | 17/6/2026 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. | |
| Modificada | Media (4.8) | 0.37% | — | Skeepers Verified Reviews (avis Verifies) | 16/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Geminilabs Site Reviews | 2/5/2023 | 17/6/2026 | The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.44% | — | Ms-reviews Project Ms-reviews | 24/4/2023 | 17/6/2026 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.63% | — | Richplugins Plugin FOR Google Reviews | 15/3/2023 | 17/6/2026 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | |
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Media (5.4) | 0.63% | — | Post Views Count Project Post Views Count | 21/2/2023 | 17/6/2026 | The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also… | |
| Modificada | Media (5.4) | 0.64% | — | Judge Product Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.51% | — | Trustindex Widgets FOR Google Reviews | 30/1/2023 | 17/6/2026 | The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (4.3) | 0.53% | — | Richplugins Plugin FOR Google Reviews | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress. | |
| Modificada | Alta (7.5) | 0.91% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress | |
| Modificada | Alta (8.8) | 0.38% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | |
| Modificada | Alta (8.8) | 1.0% | — | Cusrev Customer Reviews FOR Woocommerce | 23/9/2022 | 17/6/2026 | Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | |
| Modificada | Media (6.5) | 0.43% | — | Yotpo Reviews FOR Woocommerce Project Yotpo Reviews FOR Woocommerce | 22/8/2022 | 17/6/2026 | The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (5.3) | 0.85% | — | Wbcomdesigns Buddypress Group Reviews | 18/7/2022 | 17/6/2026 | The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for… | |
| Modificada | Media (4.8) | 0.59% | — | Wpreviewslider WP Zillow Review Slider | 20/6/2022 | 17/6/2026 | The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite) | |
| Modificada | Media (4.8) | 0.75% | — | Google Places Reviews Project Google Places Reviews | 13/6/2022 | 17/6/2026 | The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (5.4) | 0.78% | — | Jenkins Team Views | 15/2/2022 | 17/6/2026 | Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission. | |
| Modificada | Media (4.8) | 0.56% | — | Etoilewebdesign Ultimate Reviews | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15). | |
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 3/1/2022 | 17/6/2026 | The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin | |
| Modificada | Media (6.5) | 1.5% | — | Implecode Reviews Plus | 23/11/2021 | 17/6/2026 | The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page |