Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.29%—Motopress Hotel BookingAI30/7/202630/7/2026
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and…
AplazadaMedia (6.8)0.39%—Thimpress WP Hotel BookingAI30/7/202630/7/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
AplazadaAlta (7.5)1.2%—BuddypressAI30/7/202630/7/2026
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible…
Pendiente de análisisAlta (8.6)0.25%—Wordpress Coding StandardsAI28/7/20269/9/2026
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as…
AplazadaMedia (6.4)0.38%—GamipressAI28/7/202628/7/2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes…
AplazadaMedia (5.3)0.33%—Mappresspro MappressAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
AplazadaMedia (6.5)0.22%—Wordpress Social Login AND RegisterAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
AplazadaCrítica (9.3)0.40%—GamipressAI27/7/202627/7/2026
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
AplazadaAlta (8.2)0.43%💥 PoCBookingpress Appointment Booking PROAI27/7/202627/7/2026
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
AplazadaMedia (6.4)0.33%—Thimpress WP Hotel BookingAI24/7/202624/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.4)0.36%—Lightpress LightboxAI24/7/202624/7/2026
The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where this.href is…
AplazadaBaja (1.9)1.1%—Bahmutov Find-cypress-specsAI23/7/202623/7/2026
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has…
AplazadaMedia (5.4)0.14%—Melapress WP Activity LOGAIMelapress WP Activity LOG PremiumAI23/7/20265/8/2026
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
AplazadaMedia (6.5)0.22%—Nerdpress Hubbub LiteAI23/7/202623/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
AplazadaMedia (6.1)0.25%—Wpcompress WP CompressAI23/7/202623/7/2026
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's…
AplazadaAlta (8.8)0.53%—Nchsoftware ExpresszipAI22/7/20266/10/2026
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
AplazadaMedia (5.3)0.30%—Wp-feedstats Wordpress PluginAI22/7/202622/7/2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
AplazadaMedia (5.4)0.29%—ThumbpressAI20/7/202620/7/2026
The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.
AplazadaMedia (5.4)0.14%💥 PoCWp-feedstats Wordpress PluginAI20/7/202620/7/2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's…
AplazadaAlta (7.1)0.25%—Thimpress LearnpressAI20/7/202620/7/2026
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.
ModificadaCrítica (9.8)10%⚠ Explotación activa💥 ExploitWordpress17/7/20267/10/2026
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
ModificadaMedia (5.9)5.9%⚠ Explotación activa💥 ExploitWordpress17/7/20267/10/2026
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
AplazadaMedia (6.1)0.69%💥 ExploitThimpress WP Hotel BookingAI17/7/202617/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.5)0.68%—Thimpress LearnpressAI17/7/202617/7/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists,…
AplazadaAlta (8.8)1.1%—ProfilepressAI17/7/202617/7/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an…