Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.35%—Wpmet FundengineAI25/8/202626/8/2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.37%—Wpmet FundengineAI25/8/202626/8/2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)0.56%—Wpmet FundengineAI20/8/202620/8/2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
AplazadaCrítica (9.8)0.56%—Wpmet FundengineAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
AplazadaMedia (6.5)0.37%—Wpmet FundengineAI27/7/202627/7/2026
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
AplazadaMedia (6.5)0.33%—Roxnor Wp-fundraising-donationAIWpmet FundengineAI13/7/202613/7/2026
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
AnalizadaAlta (8.8)0.43%—Wpmet Fundengine1/8/202417/6/2026
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaCrítica (9.8)7.9%—Wpmet Fundengine8/6/202217/6/2026
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users