Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.29% | — | Wordpress Backup MigrationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Aplazada | Media (5.5) | 0.34% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root. | |
| Aplazada | Media (5.5) | 0.38% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. | |
| Aplazada | Media (6.6) | 0.26% | — | Wpvivid Backup Migration StagingAI | 30/8/2026 | 3/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Wpvivid Backup Migration StagingAI | 16/8/2026 | 26/8/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the… | |
| Aplazada | Media (6.5) | 0.51% | — | Backupbliss Backup MigrationAI | 15/8/2026 | 26/8/2026 | The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing… | |
| Aplazada | Alta (7.2) | 3.0% | — | Backupbliss Backup MigrationAI | 5/8/2026 | 12/8/2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell… | |
| Aplazada | Media (4.9) | 0.44% | — | Wpvivid Backup MigrationAI | 1/8/2026 | 12/8/2026 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in… | |
| Aplazada | Alta (7.5) | 0.42% | — | Backupbliss Backup MigrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions. | |
| Aplazada | Media (6.6) | 0.78% | — | Backupbliss Backup MigrationAI | 6/6/2026 | 23/7/2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP… | |
| Aplazada | Media (4.9) | 0.97% | — | Learnpress Backup MigrationAI | 6/6/2026 | 23/7/2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read… | |
| Aplazada | Baja (3.8) | 0.39% | — | Wpvivid Backup MigrationAI | 6/6/2026 | 23/7/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.31% | — | Inisev Backup MigrationAI | 5/5/2026 | 17/6/2026 | WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct… | |
| Aplazada | Media (5.3) | 0.56% | — | Backupbliss Backup MigrationAI | 7/4/2026 | 30/9/2026 | The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates against hardcoded tokens which are publicly… | |
| Aplazada | Crítica (9.8) | 33% | — | Wpvivid Backup MigrationAI | 11/2/2026 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files.… | |
| Aplazada | Baja (2.7) | 0.41% | — | Wpvivid Backup MigrationAI | 21/12/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location.… | |
| Aplazada | Media (5.9) | 0.28% | — | Backupbliss Backup MigrationAI | 24/11/2025 | 17/6/2026 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication. | |
| Aplazada | Alta (8.8) | 0.80% | — | Backupbliss Backup MigrationAI | 4/1/2025 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a… | |
| Aplazada | Media (5.3) | 0.44% | — | Inisev Backup MigrationAI | 18/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3. | |
| Modificada | Alta (7.5) | 2.1% | — | Backupbliss Backup Migration | 11/1/2024 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which… | |
| Modificada | Alta (7.5) | 0.69% | — | Backupbliss Backup Migration | 1/1/2024 | 17/6/2026 | The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups. | |
| Modificada | Alta (7.2) | 31% | — | Backupbliss Backup Migration | 23/12/2023 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system. | |
| Modificada | Crítica (9.8) | 1.4% | — | Backupbliss Backup Migration | 23/12/2023 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files,… | |
| Modificada | Crítica (9.8) | 6.4% | — | Backupbliss Backup Migration | 23/12/2023 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability… | |
| Modificada | Crítica (9.8) | 98% | — | Backupbliss Backup Migration | 15/12/2023 | 17/6/2026 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This… |