Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.99%—GmfeedAI29/9/202630/9/2026
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of…
AplazadaMedia (6.8)0.24%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (4.1)0.18%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
AplazadaMedia (4.9)0.19%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an…
AplazadaMedia (4.1)0.18%—Etruel Wpematico RSS Feed FetcherAI27/9/202628/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the…
AplazadaMedia (6.8)0.24%—Etruel Wpematico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any…
AplazadaBaja (2.7)0.22%—Wpecom Wpeomatico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including…
AplazadaMedia (6.8)0.24%—Wpematico RSS Feed FetcherAI24/9/202624/9/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign.
AplazadaMedia (4.9)1.1%—CTX FeedAI22/9/202622/9/2026
The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated attackers, with shop manager-level access and…
AplazadaMedia (6.4)0.41%—Smashballoon Custom Twitter FeedsAI18/9/202618/9/2026
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaAlta (8.5)0.36%—Product Feed ManagerAI17/9/202617/9/2026
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
AplazadaCrítica (9.8)0.50%—Private Feed KEYAI17/9/202618/9/2026
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
AplazadaMedia (4.9)0.33%—Product XML Feed ManagerAI12/9/202614/9/2026
The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that…
AplazadaMedia (6.5)0.26%—Wpmr Google Feed Manager FOR WoocommerceAI9/9/20269/9/2026
The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AplazadaAlta (7.1)0.35%—Pixelyoursite EDD Product Catalog FeedAI8/9/20268/9/2026
The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated…
AplazadaMedia (6.8)0.43%—Wp-feedstats Wordpress PluginAI5/9/20268/9/2026
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who…
AplazadaAlta (8.2)0.20%—Wp-feedstats Wordpress PluginAI2/9/20263/9/2026
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
AplazadaAlta (7.5)0.39%—Surefeedback Client SiteAI27/8/202628/8/2026
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
AplazadaAlta (8.8)0.69%—Etruel Wpematico RSS Feed FetcherAI22/8/202624/8/2026
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.9)0.47%—CTX FeedAI18/8/202620/8/2026
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
AplazadaMedia (6.4)0.33%—Smashballoon Social Post FeedAI16/8/202620/8/2026
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.5)0.43%—Adtribes Product Feed PROAI15/8/202626/8/2026
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
AplazadaBaja (1.9)0.14%—Feedmob Fm-mcp-serversAI14/8/202614/8/2026
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be…
AplazadaMedia (5.5)0.31%—Feedzy RSS AggregatorAI10/8/202626/8/2026
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and…
AplazadaCrítica (9.1)0.82%—CTX FeedAI6/8/202612/8/2026
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.