Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

814 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.15%—Quizandsurveymaster Quiz AND Survey MasterAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
AplazadaMedia (4.2)0.12%—MasterstudylmsAI25/9/202625/9/2026
The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their…
AplazadaMedia (4.3)0.15%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
AplazadaMedia (5.3)0.18%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has…
AplazadaMedia (4.3)0.15%—Masterstudies LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.
AplazadaAlta (7.2)0.36%—MasterstudylmsAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an…
AplazadaMedia (4.3)0.18%—Masteriyo LMSAI24/9/202624/9/2026
The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed…
AplazadaMedia (4.3)0.16%—Masteriyo LMSAI24/9/202624/9/2026
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the…
AplazadaMedia (4.3)0.20%—MasterstudylmsAI23/9/202623/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt…
AplazadaMedia (4.6)0.09%—MasterstudylmsAI23/9/202623/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be…
AplazadaMedia (6.8)0.24%—Masterstickies Master SliderAI20/9/202621/9/2026
The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed.…
AplazadaAlta (8.8)0.51%—Master BlocksAI19/9/202621/9/2026
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
AplazadaAlta (8.1)0.58%—Master-addons Master Addons FOR ElementorAI18/9/202619/9/2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an…
AplazadaBaja (2.7)0.30%—MasterstudylmsAI18/9/202618/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of…
AplazadaBaja (3.8)0.32%—MasterstudylmsAI18/9/202618/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and…
AplazadaAlta (7.6)0.38%—WpmasteroolkitAI17/9/202617/9/2026
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
AplazadaMedia (5.3)0.30%—Master-addons Master AddonsAI17/9/202618/9/2026
The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
AplazadaBaja (2.7)0.30%—Masteriyo LMSAI12/9/202614/9/2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
AplazadaMedia (6.8)0.43%—Masteriyo LMSAI12/9/202614/9/2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
AplazadaCrítica (9.9)0.64%—Masteriyo LMSAI12/9/202614/9/2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin…
AplazadaMedia (5.3)0.31%—Quizandsurveymaster Quiz AND Survey MasterAI11/9/202611/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
AplazadaMedia (5.3)0.29%—Masteriyo - LMSAI11/9/202611/9/2026
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
AplazadaAlta (8.8)0.52%—Masteriyo - LMSAI11/9/202611/9/2026
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
AplazadaAlta (7.1)0.32%—Jeweltheme Master Addons FOR ElementorAI11/9/202611/9/2026
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
AplazadaMedia (5.3)0.32%—Masteriyo LMSAI9/9/20269/9/2026
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets…