Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.19% | — | Themeisle Auto Featured ImageAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4. | |
| Aplazada | Media (4.3) | 0.30% | — | Cm-wp Auto Featured ImageAI | 16/12/2025 | 17/6/2026 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (4.3) | 0.37% | — | Cm-wp Auto Featured ImageAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.1.2. | |
| Aplazada | Media (6.1) | 0.38% | — | Auto Featured Image From TitleAI | 1/10/2024 | 17/6/2026 | The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (8.8) | 0.79% | — | Auto-featured-image Project Auto-featured-image | 27/6/2024 | 17/6/2026 | The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with contributor-level and above permissions, to… | |
| Aplazada | Media (6.4) | 0.26% | — | Cm-wp Auto Featured ImageAI | 31/5/2024 | 17/6/2026 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary… | |
| Aplazada | Media (4.4) | 0.27% | — | Cm-wp Auto Featured ImageAI | 29/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail).This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.0.0. | |
| Modificada | Alta (8.8) | 1.6% | — | Cm-wp Auto Featured Image | 13/3/2023 | 17/6/2026 | The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation. | |
| Modificada | Media (6.1) | 0.80% | — | Cm-wp Auto Featured Image | 13/12/2021 | 17/6/2026 | The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue. |