Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.32%—Fluentforms Fluent Forms PROAI31/8/20261/9/2026
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
AplazadaAlta (7.5)0.35%—Fluentforms Fluent Forms PRO ADD ON PackAI31/8/20261/9/2026
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
AplazadaAlta (7.1)0.25%—Fluentforms Fluent Forms PRO ADD ON PackAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
AplazadaCrítica (9.3)0.67%—Fluent Forms PROAI13/8/20269/9/2026
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a…
AplazadaAlta (8.8)0.55%—Fluent Forms PRO ADD ON PackAI26/7/202627/7/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of…
AplazadaMedia (6.5)0.37%—Fluentforms Fluent Forms PRO ADD ON PackAI5/3/202617/6/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which…
AplazadaAlta (7.2)0.27%—Fluentforms Fluent Forms PROAI5/3/202617/6/2026
The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined…
AplazadaAlta (7.5)0.14%—Fluentforms Fluent Forms PRO ADD ON PackAI27/2/202617/6/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in…
AplazadaMedia (5.4)0.24%—Fluentforms Fluent Forms PRO ADD ON PackAI9/2/202617/6/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations…