Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.38%—Wplegalpages WP Legal PagesAI24/8/202626/8/2026
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
AplazadaMedia (5.3)0.25%—Wpwax Legal PagesAI21/11/202517/6/2026
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.
AplazadaMedia (5.3)0.30%—Wplegalpages WP Legal PagesAI1/11/202517/6/2026
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and including, 3.5.1. This makes it possible for…
AplazadaAlta (8.1)0.27%—Wplegalpages WP Legal PagesAI18/9/202517/6/2026
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the wplp_gdpr_install_plugin_ajax_handler() function in all versions up to, and including, 3.4.3. This makes it…
AplazadaMedia (6.5)0.38%—Wpwax Legal PagesAI19/5/202517/6/2026
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.5.
AplazadaMedia (4.3)0.18%—Wplegalpages WP Legal PagesAI25/12/202417/6/2026
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation on the 'create_popup_delete_process' function. This makes it…
AplazadaMedia (4.3)0.21%—Wpwax Legal PagesAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.4.2.
ModificadaAlta (8)0.21%—Wpwax Legal Pages15/3/202417/6/2026
Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.
ModificadaAlta (8.8)0.25%—Wpwax Legal Pages22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin <= 1.3.8 versions.
ModificadaMedia (6.5)0.87%—Wplegalpages WP Legal Pages26/9/201917/6/2026
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
Orbitaley — Vulnerabilidades