Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—GivewpAI30/9/202630/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
AplazadaMedia (6.5)0.33%—GivewpAI30/9/202630/9/2026
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
AplazadaAlta (7.1)0.20%—GivewpAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
AplazadaCrítica (9.1)0.30%—Stellarwp GivewpAI30/9/202630/9/2026
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
AplazadaMedia (6.5)0.31%—GivewpAI21/9/202621/9/2026
The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaAlta (8.1)0.38%—GivewpAI16/9/202617/9/2026
The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one,…
AplazadaCrítica (10)2.3%—Stellarwp GivewpAILiquidweb GivewpAI28/8/202628/8/2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
AplazadaMedia (6.4)0.36%—GivewpAI28/8/202628/8/2026
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up to, and including, 4.14.4. This is due to insufficient input sanitization and output escaping on the continue_button_title and display_style shortcode…
AplazadaMedia (6.5)0.27%—GivewpAI18/8/202620/8/2026
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
AplazadaMedia (6.5)0.27%—GivewpAI18/8/202620/8/2026
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
AplazadaMedia (6.5)0.22%—GivewpAI13/8/202614/8/2026
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
AplazadaMedia (5.3)0.29%—GivewpAI13/8/202614/8/2026
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
AplazadaAlta (7.1)0.25%—GivewpAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
AplazadaAlta (7.5)0.43%—GivewpAI31/7/202626/8/2026
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
AplazadaMedia (5.3)0.30%—GivewpAI31/7/202626/8/2026
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.
AplazadaMedia (6.8)0.43%—GivewpAI30/7/202630/7/2026
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
AplazadaAlta (7.1)0.25%—GivewpAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
AplazadaMedia (5.4)0.14%—GivewpAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
AplazadaMedia (6.4)0.36%—GivewpAI16/7/202616/7/2026
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.4)0.41%—GivewpAI2/7/20262/7/2026
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.4)0.42%—GivewpAI1/7/20261/7/2026
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to insufficient input sanitization and output…
AplazadaMedia (4.3)0.23%—GivewpAI1/7/20261/7/2026
The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged…
AplazadaAlta (7.1)0.25%—GivewpAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
AplazadaAlta (7.1)0.25%—Stellarwp GivewpAI1/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.
AplazadaMedia (5.3)0.31%—Stellarwp GivewpAI29/4/202617/6/2026
Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.