Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Elis Wordcents Adsense Widget With AnalyticsAI15/6/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
AplazadaMedia (4.3)0.18%—Country Blocker FOR AdsenseAI19/2/202617/6/2026
The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged…
AplazadaMedia (5.3)0.31%—Themebeez Universal Google Adsense AND ADS ManagerAI23/1/202617/6/2026
Missing Authorization vulnerability in themebeez Universal Google Adsense and Ads manager universal-google-adsense-and-ads-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Google Adsense and Ads manager: from n/a through <= 1.1.8.
AplazadaMedia (5.9)0.21%—THE Plugin Factory Google Adsense FOR Responsive Design GardAI24/12/20255/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory Google AdSense for Responsive Design – GARD google-adsense-for-responsive-design-gard allows DOM-Based XSS.This issue affects Google AdSense for Responsive Design – GARD: from n/a through <= 2.23.
AplazadaMedia (5.3)0.48%—Rtakao Sandwich AdsenseAI9/4/202517/6/2026
Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sandwich Adsense: from n/a through <= 4.0.2.
AplazadaAlta (7.1)0.18%—Hotvanrod Adsense Privacy PolicyAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored XSS.This issue affects AdSense Privacy Policy: from n/a through <= 1.1.1.
AplazadaAlta (7.2)0.51%—Revenueflex Auto AD Inserter Increase Google Adsense AND AD Manager RevenueAI24/2/202517/6/2026
Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5.
AplazadaMedia (4.3)0.19%—Magazine3 Ads-for-wpAIGoogle AdsenseAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Google Adsense & Banner Ads by AdsforWP ads-for-wp allows Cross Site Request Forgery.This issue affects Google Adsense & Banner Ads by AdsforWP: from n/a through <= 1.9.28.
ModificadaMedia (4.8)0.47%—Wpadvancedads Advanced ADS - AD Manager & Adsense8/11/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress.
ModificadaMedia (4.3)0.43%—Tipsandtricks-hq WP Simple Adsense Insertion8/6/202217/6/2026
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.
ModificadaMedia (6.1)1.5%—Google Adsense Project Google Adsense13/8/201917/6/2026
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (6.1)1.1%—Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois17/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php.
ModificadaCrítica (9.1)2.3%—Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking6/10/201617/6/2026
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
ModificadaMedia (4.3)1.6%—Whydowork Adsense Project Whydowork Adsense26/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_adsense page to wp-admin/options-general.php.
ModificadaMedia (6.8)2.7%—Whydowork Adsense Project Whydowork Adsense26/11/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php.
ModificadaMedia (6.8)1.2%—Askapache Firefox Adsense3/1/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the aafireadcode parameter to…
ModificadaMedia (6.8)0.98%—Thulasidas Easy-adsense-lite5/5/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
ModificadaMedia (6)1.5%—Johntp Adsense-deluxe22/5/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in adsense-deluxe.php in the AdSense-Deluxe 0.x plugin for WordPress allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors.