Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Elis Wordcents Adsense Widget With AnalyticsAI | 15/6/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. | |
| Aplazada | Media (4.3) | 0.18% | — | Country Blocker FOR AdsenseAI | 19/2/2026 | 17/6/2026 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Aplazada | Media (5.3) | 0.31% | — | Themebeez Universal Google Adsense AND ADS ManagerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in themebeez Universal Google Adsense and Ads manager universal-google-adsense-and-ads-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Google Adsense and Ads manager: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.9) | 0.21% | — | THE Plugin Factory Google Adsense FOR Responsive Design GardAI | 24/12/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory Google AdSense for Responsive Design – GARD google-adsense-for-responsive-design-gard allows DOM-Based XSS.This issue affects Google AdSense for Responsive Design – GARD: from n/a through <= 2.23. | |
| Aplazada | Media (5.3) | 0.48% | — | Rtakao Sandwich AdsenseAI | 9/4/2025 | 17/6/2026 | Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sandwich Adsense: from n/a through <= 4.0.2. | |
| Aplazada | Alta (7.1) | 0.18% | — | Hotvanrod Adsense Privacy PolicyAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored XSS.This issue affects AdSense Privacy Policy: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.2) | 0.51% | — | Revenueflex Auto AD Inserter Increase Google Adsense AND AD Manager RevenueAI | 24/2/2025 | 17/6/2026 | Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5. | |
| Aplazada | Media (4.3) | 0.19% | — | Magazine3 Ads-for-wpAIGoogle AdsenseAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Google Adsense & Banner Ads by AdsforWP ads-for-wp allows Cross Site Request Forgery.This issue affects Google Adsense & Banner Ads by AdsforWP: from n/a through <= 1.9.28. | |
| Modificada | Media (4.8) | 0.47% | — | Wpadvancedads Advanced ADS - AD Manager & Adsense | 8/11/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress. | |
| Modificada | Media (4.3) | 0.43% | — | Tipsandtricks-hq WP Simple Adsense Insertion | 8/6/2022 | 17/6/2026 | The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form. | |
| Modificada | Media (6.1) | 1.5% | — | Google Adsense Project Google Adsense | 13/8/2019 | 17/6/2026 | The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (6.1) | 1.1% | — | Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois | 17/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php. | |
| Modificada | Crítica (9.1) | 2.3% | — | Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking | 6/10/2016 | 17/6/2026 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | |
| Modificada | Media (4.3) | 1.6% | — | Whydowork Adsense Project Whydowork Adsense | 26/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_adsense page to wp-admin/options-general.php. | |
| Modificada | Media (6.8) | 2.7% | — | Whydowork Adsense Project Whydowork Adsense | 26/11/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php. | |
| Modificada | Media (6.8) | 1.2% | — | Askapache Firefox Adsense | 3/1/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the aafireadcode parameter to… | |
| Modificada | Media (6.8) | 0.98% | — | Thulasidas Easy-adsense-lite | 5/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. | |
| Modificada | Media (6) | 1.5% | — | Johntp Adsense-deluxe | 22/5/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in adsense-deluxe.php in the AdSense-Deluxe 0.x plugin for WordPress allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. |