Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | — | — | Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due… | |
| Aplazada | Media (6.1) | — | — | Calculatedfields Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to… | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.18% | — | Calculated Fields FormAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | |
| Aplazada | Alta (8.1) | 0.21% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to… | |
| Aplazada | Baja (3.3) | 0.13% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting… | |
| Aplazada | Baja (3.7) | 0.25% | — | Secure Custom FieldsAI | 19/9/2026 | 21/9/2026 | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mipl Grouped Checkout Fields FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Media (4.3) | 0.43% | — | Checkout Custom Fields Builder FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.51% | — | Repeater Fields FOR Gravity FormsAI | 9/9/2026 | 9/9/2026 | The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.1) | 0.37% | — | Acfextended Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities… | |
| Aplazada | Alta (8.1) | 0.23% | — | Advancedcustomfields Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Custom User Registration Fields FOR WoocommerceAI | 29/8/2026 | 1/9/2026 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in… | |
| Aplazada | Alta (7.5) | 0.53% | — | Advanced Product FieldsAI | 22/8/2026 | 24/8/2026 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid… | |
| Aplazada | Media (6.5) | 0.22% | — | Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Tychesoftwares Product Input Fields FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on… | |
| Aplazada | Media (4.3) | 0.27% | — | Advancedcustomfields Font Awesome FieldAI | 6/8/2026 | 12/8/2026 | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | |
| Aplazada | Crítica (10) | 0.57% | — | Custom FieldsAI | 5/8/2026 | 26/8/2026 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover. | |
| Aplazada | Media (5.4) | 0.23% | — | Admin Columns FOR ACF FieldsAI | 1/8/2026 | 26/8/2026 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users… | |
| Aplazada | Alta (8.1) | 0.41% | — | Custom Fields Account Registration FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator… | |
| Aplazada | Alta (8.8) | 0.51% | — | Product Addons AND Product Options With Custom FieldsAI | 22/7/2026 | 22/7/2026 | The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any… | |
| Aplazada | Media (6.4) | 0.32% | — | Smart Custom FieldsAI | 17/7/2026 | 17/7/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (6.5) | 0.47% | — | Blocks FOR ACF FieldsAI | 9/7/2026 | 9/7/2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic… | |
| Aplazada | Alta (7.2) | 0.54% | — | Advanced Product FieldsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. |