Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.47% | — | Mainwp ChildAI | 27/7/2026 | 27/7/2026 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an… | |
| Aplazada | Alta (7.5) | 0.31% | — | Mainwp ChildAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | |
| Aplazada | Media (5.3) | 0.44% | — | Mainwp Child ReportsAI | 8/4/2026 | 24/7/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.1) | 2.4% | — | Mainwp ChildAI | 13/12/2024 | 17/6/2026 | The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it… | |
| Analizada | Alta (8.8) | 0.31% | — | Mainwp Child | 8/8/2024 | 17/6/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can… | |
| Modificada | Media (5.4) | 0.20% | — | Mainwp Child Reports | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1. | |
| Modificada | Alta (7.5) | 0.66% | — | Mainwp Child | 27/6/2023 | 17/6/2026 | The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a… | |
| Modificada | Alta (7.2) | 1.3% | — | Mainwp Child | 23/11/2021 | 17/6/2026 | The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed | |
| Modificada | Alta (7.2) | 1.4% | — | Mainwp Child Reports | 18/10/2021 | 17/6/2026 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue |