Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.41%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaMedia (5.4)0.40%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaCrítica (9.8)1.6%—Etoilewebdesign Ultimate Reviews7/6/202317/6/2026
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
ModificadaMedia (4.8)0.37%—Skeepers Verified Reviews (avis Verifies)16/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13 versions.
ModificadaMedia (4.8)0.50%—Geminilabs Site Reviews2/5/202317/6/2026
The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (5.4)0.44%—Ms-reviews Project Ms-reviews24/4/202317/6/2026
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.63%—Richplugins Plugin FOR Google Reviews15/3/202317/6/2026
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
ModificadaAlta (8.8)0.90%—Prestashop Advanced Reviews14/3/202317/6/2026
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
ModificadaMedia (5.4)0.63%—Post Views Count Project Post Views Count21/2/202317/6/2026
The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)1.1%—Cusrev Customer Reviews FOR Woocommerce13/2/202317/6/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also…
ModificadaMedia (5.4)0.64%—Judge Product Reviews FOR Woocommerce13/2/202317/6/2026
The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.51%—Trustindex Widgets FOR Google Reviews30/1/202317/6/2026
The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaMedia (4.3)0.53%—Richplugins Plugin FOR Google Reviews18/11/202217/6/2026
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
ModificadaAlta (7.5)0.91%—Cusrev Customer Reviews FOR Woocommerce23/9/202217/6/2026
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
ModificadaAlta (8.8)0.38%—Cusrev Customer Reviews FOR Woocommerce23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
ModificadaAlta (8.8)1.0%—Cusrev Customer Reviews FOR Woocommerce23/9/202217/6/2026
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
ModificadaMedia (6.5)0.43%—Yotpo Reviews FOR Woocommerce Project Yotpo Reviews FOR Woocommerce22/8/202217/6/2026
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
ModificadaMedia (5.3)0.85%—Wbcomdesigns Buddypress Group Reviews18/7/202217/6/2026
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for…
ModificadaMedia (4.8)0.59%—Wpreviewslider WP Zillow Review Slider20/6/202217/6/2026
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)
ModificadaMedia (4.8)0.75%—Google Places Reviews Project Google Places Reviews13/6/202217/6/2026
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped…
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (5.4)0.78%—Jenkins Team Views15/2/202217/6/2026
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
ModificadaMedia (4.8)0.56%—Etoilewebdesign Ultimate Reviews28/1/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
ModificadaMedia (6.1)1.3%—Geminilabs Site Reviews3/1/202217/6/2026
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
ModificadaMedia (6.5)1.5%—Implecode Reviews Plus23/11/202117/6/2026
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
Orbitaley — Vulnerabilidades