Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Openai Chatbot FOR Wordpress HelperAI | 2/7/2026 | 6/10/2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simple PAY WordpressAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | |
| Pendiente de análisis | Media (6.7) | 0.18% | — | Hypr PasswordlessAI | 25/6/2026 | 25/6/2026 | Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1. | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Alta (8.7) | 0.63% | — | Wordpress Time CapsuleAI | 20/6/2026 | 29/9/2026 | WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the… | |
| Aplazada | Alta (8.6) | 0.26% | — | Wordpress Dating ThemeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. | |
| Aplazada | Alta (8.8) | 0.18% | — | Wordpress Dating ThemeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 6/10/2026 | Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Crítica (10) | 0.43% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 6/10/2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Media (4.3) | 0.13% | — | Andy Moyle Emergency Password ResetAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Geomywp GEO MY WordpressAI | 16/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elex Wordpress Helpdesk & Customer Ticketing SystemAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Elis Wordcents Adsense Widget With AnalyticsAI | 15/6/2026 | 7/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. | |
| Aplazada | Media (6.9) | 0.13% | — | Wordpress More FieldsAI | 15/6/2026 | 17/6/2026 | WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit… | |
| Aplazada | Media (6.9) | 0.69% | — | Wordpress Imdb Profile WidgetAI | 15/6/2026 | 17/6/2026 | WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.php containing… | |
| Aplazada | Alta (8.7) | 0.32% | — | Wpultimate Wordpress Ultimate Product CatalogAI | 15/6/2026 | 17/6/2026 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file… | |
| Aplazada | Media (5.3) | 0.10% | — | Wordpress Lazy Content SliderAI | 15/6/2026 | 17/6/2026 | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify… | |
| Aplazada | Media (5.1) | 0.22% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts… | |
| Aplazada | Alta (8.8) | 0.24% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL… | |
| Aplazada | Alta (8.8) | 0.30% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter… | |
| Aplazada | Alta (7.4) | 0.26% | — | Avira Password ManagerAIMozilla FirefoxAI | 12/6/2026 | 23/7/2026 | Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when used with Mozilla… | |
| Pendiente de análisis | Crítica (9.9) | 0.74% | — | Cpanel Wordpress ToolkitAI | 12/6/2026 | 17/6/2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | |
| Analizada | Alta (7.1) | 0.44% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft Word | 9/6/2026 | 23/7/2026 | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |