Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Motopress Hotel BookingAI | 30/7/2026 | 30/7/2026 | The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and… | |
| Aplazada | Media (6.8) | 0.39% | — | Thimpress WP Hotel BookingAI | 30/7/2026 | 30/7/2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks. | |
| Aplazada | Alta (7.5) | 1.2% | — | BuddypressAI | 30/7/2026 | 30/7/2026 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible… | |
| Pendiente de análisis | Alta (8.6) | 0.25% | — | Wordpress Coding StandardsAI | 28/7/2026 | 9/9/2026 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as… | |
| Aplazada | Media (6.4) | 0.38% | — | GamipressAI | 28/7/2026 | 28/7/2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (5.3) | 0.33% | — | Mappresspro MappressAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wordpress Social Login AND RegisterAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GamipressAI | 27/7/2026 | 27/7/2026 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | |
| Aplazada | Alta (8.2) | 0.43% | 💥 PoC | Bookingpress Appointment Booking PROAI | 27/7/2026 | 27/7/2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. | |
| Aplazada | Media (6.4) | 0.33% | — | Thimpress WP Hotel BookingAI | 24/7/2026 | 24/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.36% | — | Lightpress LightboxAI | 24/7/2026 | 24/7/2026 | The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is… | |
| Aplazada | Baja (1.9) | 1.1% | — | Bahmutov Find-cypress-specsAI | 23/7/2026 | 23/7/2026 | A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has… | |
| Aplazada | Media (5.4) | 0.14% | — | Melapress WP Activity LOGAIMelapress WP Activity LOG PremiumAI | 23/7/2026 | 5/8/2026 | Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Nerdpress Hubbub LiteAI | 23/7/2026 | 23/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. | |
| Aplazada | Media (6.1) | 0.25% | — | Wpcompress WP CompressAI | 23/7/2026 | 23/7/2026 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's… | |
| Aplazada | Alta (8.8) | 0.53% | — | Nchsoftware ExpresszipAI | 22/7/2026 | 6/10/2026 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Media (5.4) | 0.29% | — | ThumbpressAI | 20/7/2026 | 20/7/2026 | The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality. | |
| Aplazada | Media (5.4) | 0.14% | 💥 PoC | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Alta (7.1) | 0.25% | — | Thimpress LearnpressAI | 20/7/2026 | 20/7/2026 | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link. | |
| Modificada | Crítica (9.8) | 10% | ⚠ Explotación activa💥 Exploit | Wordpress | 17/7/2026 | 7/10/2026 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | |
| Modificada | Media (5.9) | 5.9% | ⚠ Explotación activa💥 Exploit | Wordpress | 17/7/2026 | 7/10/2026 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | |
| Aplazada | Media (6.1) | 0.69% | 💥 Exploit | Thimpress WP Hotel BookingAI | 17/7/2026 | 17/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.5) | 0.68% | — | Thimpress LearnpressAI | 17/7/2026 | 17/7/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists,… | |
| Aplazada | Alta (8.8) | 1.1% | — | ProfilepressAI | 17/7/2026 | 17/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an… |