Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.10%—Intel Neural Compressor11/8/202631/8/2026
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (5.4)0.16%—Intel Neural Compressor11/8/202628/9/2026
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AplazadaMedia (5.4)0.23%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
AplazadaMedia (5.3)0.30%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
AplazadaBaja (2.2)0.24%—Thimpress LearnpressAI10/8/202626/8/2026
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
Pendiente de análisisAlta (8.9)0.89%💥 ExploitWordpressAI7/8/20263/9/2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social…
AplazadaMedia (6.8)0.43%—DatapressAI6/8/202626/8/2026
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users…
AplazadaMedia (5.3)0.16%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching…
AplazadaMedia (5.3)0.32%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
AplazadaAlta (7.1)0.25%—Facebook FOR WordpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
AplazadaCrítica (9.3)0.40%—Wordpress File UploadAI6/8/202612/8/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
AplazadaAlta (7.1)0.34%—AnspressAI6/8/202612/8/2026
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
AplazadaAlta (7.1)0.25%—Wpdeveloper EmbedpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
AplazadaAlta (7.2)0.40%—Cozmoslabs TranslatepressAI6/8/202612/8/2026
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.85%💥 ExploitCozmoslabs TranslatepressAI5/8/202612/8/2026
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with…
AplazadaMedia (6.8)0.43%—Blubrry PowerpressAI4/8/202626/8/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
AplazadaMedia (5.8)0.33%—Wpdeveloper EmbedpressAI4/8/202626/8/2026
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind…
AplazadaMedia (6.4)0.35%—GamipressAI1/8/202612/8/2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gamipress_rank' Shortcode in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (6.4)0.33%—GamipressAI1/8/202612/8/2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in 'gamipress_achievement' in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and…
AplazadaMedia (5.3)0.39%—MailerpressAI31/7/202612/8/2026
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
AplazadaMedia (5.3)0.39%—MailpressAI31/7/202612/8/2026
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback,…
AplazadaMedia (5.4)0.24%—BuddypressAI31/7/202626/8/2026
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
AplazadaMedia (6.1)0.27%—NewstatpressAI31/7/202626/8/2026
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected…
AplazadaMedia (6.5)0.27%—Mailgun FOR WordpressAI31/7/202626/8/2026
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's…
AplazadaAlta (7.5)0.41%—Wp-feedstats Wordpress PluginAI31/7/202626/8/2026
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.