Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
–

198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.7)——Calculated Fields FormAI1/10/20261/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due…
AplazadaMedia (6.1)——Calculatedfields Calculated Fields FormAI1/10/20261/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to…
AplazadaAlta (7.2)0.24%—Repeater Fields FOR Elementor FormsAI25/9/202625/9/2026
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (7.1)0.18%—Calculated Fields FormAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
AplazadaAlta (8.1)0.21%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to…
AplazadaBaja (3.3)0.13%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting…
AplazadaBaja (3.7)0.25%—Secure Custom FieldsAI19/9/202621/9/2026
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
AplazadaCrítica (9.8)1.1%—Mipl Grouped Checkout Fields FOR WoocommerceAI11/9/202611/9/2026
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated…
AplazadaAlta (8.6)0.53%—Studiowombat Advanced Product Fields Extended FOR WoocommerceAI10/9/202611/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
AplazadaMedia (4.3)0.43%—Checkout Custom Fields Builder FOR WoocommerceAI9/9/20269/9/2026
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.51%—Repeater Fields FOR Gravity FormsAI9/9/20269/9/2026
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.1)0.37%—Acfextended Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities…
AplazadaAlta (8.1)0.23%—Advancedcustomfields Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a…
AplazadaCrítica (9.8)0.40%—Custom User Registration Fields FOR WoocommerceAI29/8/20261/9/2026
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in…
AplazadaAlta (7.5)0.53%—Advanced Product FieldsAI22/8/202624/8/2026
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid…
AplazadaMedia (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AplazadaCrítica (9.8)0.83%—Tychesoftwares Product Input Fields FOR WoocommerceAI10/8/202626/8/2026
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on…
AplazadaMedia (4.3)0.27%—Advancedcustomfields Font Awesome FieldAI6/8/202612/8/2026
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
AplazadaCrítica (10)0.57%—Custom FieldsAI5/8/202626/8/2026
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
AplazadaMedia (5.4)0.23%—Admin Columns FOR ACF FieldsAI1/8/202626/8/2026
The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users…
AplazadaAlta (8.1)0.41%—Custom Fields Account Registration FOR WoocommerceAI27/7/202627/7/2026
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator…
AplazadaAlta (8.8)0.51%—Product Addons AND Product Options With Custom FieldsAI22/7/202622/7/2026
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any…
AplazadaMedia (6.4)0.32%—Smart Custom FieldsAI17/7/202617/7/2026
The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaMedia (6.5)0.47%—Blocks FOR ACF FieldsAI9/7/20269/7/2026
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic…
AplazadaAlta (7.2)0.54%—Advanced Product FieldsAI15/6/202617/6/2026
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.