Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
814 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | |
| Aplazada | Media (4.2) | 0.12% | — | MasterstudylmsAI | 25/9/2026 | 25/9/2026 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their… | |
| Aplazada | Media (4.3) | 0.15% | — | Stylemixthemes Masterstudy LMSAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to. | |
| Aplazada | Media (5.3) | 0.18% | — | Stylemixthemes Masterstudy LMSAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has… | |
| Aplazada | Media (4.3) | 0.15% | — | Masterstudies LMSAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account. | |
| Aplazada | Alta (7.2) | 0.36% | — | MasterstudylmsAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an… | |
| Aplazada | Media (4.3) | 0.18% | — | Masteriyo LMSAI | 24/9/2026 | 24/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed… | |
| Aplazada | Media (4.3) | 0.16% | — | Masteriyo LMSAI | 24/9/2026 | 24/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the… | |
| Aplazada | Media (4.3) | 0.20% | — | MasterstudylmsAI | 23/9/2026 | 23/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt… | |
| Aplazada | Media (4.6) | 0.09% | — | MasterstudylmsAI | 23/9/2026 | 23/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be… | |
| Aplazada | Media (6.8) | 0.24% | — | Masterstickies Master SliderAI | 20/9/2026 | 21/9/2026 | The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed.… | |
| Aplazada | Alta (8.8) | 0.51% | — | Master BlocksAI | 19/9/2026 | 21/9/2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | |
| Aplazada | Alta (8.1) | 0.58% | — | Master-addons Master Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an… | |
| Aplazada | Baja (2.7) | 0.30% | — | MasterstudylmsAI | 18/9/2026 | 18/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of… | |
| Aplazada | Baja (3.8) | 0.32% | — | MasterstudylmsAI | 18/9/2026 | 18/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and… | |
| Aplazada | Alta (7.6) | 0.38% | — | WpmasteroolkitAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Master-addons Master AddonsAI | 17/9/2026 | 18/9/2026 | The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site. | |
| Aplazada | Baja (2.7) | 0.30% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses. | |
| Aplazada | Media (6.8) | 0.43% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators. | |
| Aplazada | Crítica (9.9) | 0.64% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin… | |
| Aplazada | Media (5.3) | 0.31% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Masteriyo - LMSAI | 11/9/2026 | 11/9/2026 | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Masteriyo - LMSAI | 11/9/2026 | 11/9/2026 | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Jeweltheme Master Addons FOR ElementorAI | 11/9/2026 | 11/9/2026 | Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | |
| Aplazada | Media (5.3) | 0.32% | — | Masteriyo LMSAI | 9/9/2026 | 9/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets… |