Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | MarketkingAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. | |
| Aplazada | Alta (7.1) | 0.43% | — | MarketkingAI | 22/9/2026 | 22/9/2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary vendor administrator panel pages by supplying an arbitrary vendor user ID. Attackers… | |
| Aplazada | Alta (7.1) | 0.40% | — | MarketkingAI | 22/9/2026 | 25/9/2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the complete vendor directory by sending a crafted AJAX request. Attackers can exploit the… | |
| Aplazada | Media (5.3) | 0.32% | — | MarketkingAI | 22/9/2026 | 23/9/2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vendor's product by supplying an arbitrary product ID. Attackers can bypass ownership… | |
| Aplazada | Media (5.3) | 0.33% | — | MarketkingAI | 22/9/2026 | 22/9/2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests against any order by supplying an arbitrary order ID. Attackers can submit crafted… | |
| Aplazada | Media (5.3) | 0.29% | — | Kings Plugins MarketkingAI | 4/9/2026 | 7/9/2026 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60. | |
| Aplazada | Media (5.3) | 0.29% | — | MarketkingAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Webwizards MarketkingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebWizards MarketKing marketking-multivendor-marketplace-for-woocommerce allows Stored XSS.This issue affects MarketKing: from n/a through <= 2.0.92. | |
| Aplazada | Media (4.4) | 0.26% | — | Multivendor MarketkingAI | 18/1/2025 | 17/6/2026 | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.9.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.40% | — | MarketkingAI | 25/12/2024 | 17/6/2026 | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like 'marketking_delete_team_member', 'marketkingrejectuser', 'marketking_save_profile_settings', and many more in all versions up to,… |