Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.1)0.22%—Ewww Image OptimizerAI3/10/20263/10/2026
The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (4.9)0.21%—Shortpixel Image OptimizerAI30/9/202630/9/2026
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
AplazadaMedia (6.5)0.18%—Ewww Image OptimizerAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
AplazadaMedia (4.4)0.17%—Ewww Image OptimizerAI30/9/202630/9/2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network,…
AplazadaMedia (6.6)0.35%—Ewww Image OptimizerAI30/9/202630/9/2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a…
AplazadaMedia (4.3)0.18%—Image OptimizerAI30/9/202630/9/2026
The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.
AplazadaAlta (7.5)0.22%—Robin Image OptimizerAI30/9/202630/9/2026
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of…
AplazadaMedia (4.3)0.16%—Robin Image OptimizerAI30/9/202630/9/2026
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin…
AplazadaAlta (8.8)0.89%—Shortpixel Image OptimizerAI18/9/202618/9/2026
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP…
AplazadaMedia (6.8)0.43%—Ewww Image OptimizerAI17/9/202618/9/2026
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views…
AplazadaAlta (7.2)0.28%—Ewww Image OptimizerAI3/9/20263/9/2026
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
AplazadaMedia (6.4)0.42%—Ewww Image OptimizerAI19/8/202620/8/2026
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.66%—Image OptimizerAI2/7/20262/7/2026
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they…
AplazadaAlta (7.2)0.54%—Shortpixel Image OptimizerAI15/6/202617/6/2026
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
AplazadaMedia (5.4)0.31%—Shortpixel Image OptimizerAI26/3/202617/6/2026
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the…
AplazadaMedia (4.3)0.33%—Elementor Image OptimizerAI19/2/202617/6/2026
Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.
AplazadaMedia (6.4)0.23%—Robin Image OptimizerAI5/2/202617/6/2026
The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.9)0.59%—Shortpixel Image OptimizerAI5/2/202617/6/2026
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.30%—Crush Pics Image OptimizerAI14/1/202617/6/2026
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple functions in all versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (4.3)0.15%—Image Optimizer BY WPS SKAI5/12/202517/6/2026
The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the imagopby_ajax_optimize_gallery() function. This makes it possible for unauthenticated attackers to trigger bulk…
AplazadaMedia (5.4)0.31%—Shortpixel Image OptimizerAI18/10/202517/6/2026
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers,…
ModificadaCrítica (9.8)2.0%—Pluginab Plugin A/B Image Optimizer7/2/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimizer allows Path Traversal.This issue affects Plugin A/B Image Optimizer: from n/a through <= 3.3.
AplazadaMedia (4.3)0.65%—Kraken.io Image OptimizerAI9/12/202417/6/2026
Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.
ModificadaAlta (8.8)0.39%—Shortpixel Image Optimizer1/11/202417/6/2026
Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.
AplazadaMedia (6.5)0.50%—Creative Motion Robin Image OptimizerAI1/11/202417/6/2026
Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.