Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.13% | — | Fifu Featured Image From URLAI | 1/10/2026 | 1/10/2026 | The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform… | |
| Aplazada | Media (6.8) | 0.43% | — | Featured Image With URLAI | 11/9/2026 | 11/9/2026 | The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post,… | |
| Aplazada | Media (6.5) | 0.22% | — | Fifu Featured Image From URLAI | 13/8/2026 | 14/8/2026 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | |
| Aplazada | Media (4.9) | 0.19% | — | Themeisle Auto Featured ImageAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Mer.vin Featured ImageAI | 26/6/2026 | 29/6/2026 | Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions. | |
| Aplazada | Media (5.9) | 0.24% | — | Fesomia FSM Custom Featured Image CaptionAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fesomia FSM Custom Featured Image Caption fsm-custom-featured-image-caption allows DOM-Based XSS.This issue affects FSM Custom Featured Image Caption: from n/a through <= 1.25.1. | |
| Aplazada | Media (5.3) | 0.41% | — | Featured Image From ContentAI | 27/2/2026 | 17/6/2026 | Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to fetch internal HTTP resources. Attackers can exploit insecure URL fetching and file write operations to retrieve… | |
| Aplazada | Media (4.3) | 0.23% | — | Webdevstudios Automatic Featured Images From VideosAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.21% | — | AUM Watcharapon Featured Image GeneratorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Aum Watcharapon Featured Image Generator featured-image-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image Generator: from n/a through <= 1.3.4. | |
| Aplazada | Media (5.9) | 0.20% | — | Viitorcloud Technologies PVT LTD ADD Featured Image Custom LinkAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link custom-url-to-featured-image allows DOM-Based XSS.This issue affects Add Featured Image Custom Link: from n/a through <= 2.0.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Cm-wp Auto Featured ImageAI | 16/12/2025 | 17/6/2026 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Alta (8.8) | 0.55% | — | Featured Image VIA URLAI | 5/12/2025 | 25/9/2026 | The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's… | |
| Modificada | Media (5.5) | 0.48% | — | Mer.vin Featured Image | 11/11/2025 | 17/6/2026 | The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (4.9) | 0.31% | — | Quick Featured ImagesAI | 8/11/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all versions up to, and including, 13.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.20% | — | Johnny Post List Featured Image Post List Featured ImageAI | 27/10/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List Featured Image post-list-featured-image allows Stored XSS.This issue affects Post List Featured Image: from n/a through <= 0.5.9. | |
| Aplazada | Media (4.3) | 0.24% | — | Quick Featured ImagesAI | 15/10/2025 | 17/6/2026 | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.9) | 0.33% | — | Fifu Featured Image From URLAI | 26/9/2025 | 17/6/2026 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.9) | 0.22% | — | MAT Category Featured ImagesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mat Category Featured Images category-featured-images allows Stored XSS.This issue affects Category Featured Images: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.9) | 0.23% | — | CK Macleod Category Featured Images ExtendedAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CK MacLeod Category Featured Images Extended category-featured-images-extended allows Stored XSS.This issue affects Category Featured Images Extended: from n/a through <= 1.52. | |
| Aplazada | Crítica (9.1) | 0.34% | — | Creedallyinc Bulk Featured ImageAI | 5/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Aplazada | Media (5.5) | 0.26% | — | Krasenslavov Featured Image PlusAI | 23/7/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.6 via the fip_get_image_options() function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web… | |
| Aplazada | Media (6.4) | 0.25% | — | Simple Featured ImageAI | 9/7/2025 | 17/6/2026 | The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slideshow’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Creedallyinc Bulk Featured ImageAI | 4/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Modificada | Media (4.3) | 0.29% | — | Krasenslavov Featured Image Plus | 30/5/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.38% | — | Creedally Bulk Featured ImageAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. |