Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.44%—Metabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI22/9/202622/9/2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET…
AplazadaMedia (5.5)0.38%—Metabox Meta BOXAI2/8/202626/8/2026
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
AplazadaCrítica (9.1)0.52%—Metabox Meta BOX AIOAI29/7/202630/7/2026
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and…
AplazadaMedia (6.8)1.3%—Metabox Meta BOXAI15/6/202617/6/2026
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
AplazadaMedia (4.3)0.20%—Remove Meta Boxes PER User RoleAI2/6/202622/7/2026
The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset…
AplazadaAlta (7.2)2.4%—Metabox Meta BOXAI7/3/202617/6/2026
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on…
AplazadaAlta (7.1)0.39%—Rachel Cherry Authors Autocomplete Meta BOXAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Authors Autocomplete Meta Box authors-autocomplete-meta-box allows Reflected XSS.This issue affects Authors Autocomplete Meta Box: from n/a through <= 1.2.
AplazadaAlta (7.1)0.47%—Metabox Meta BOXAI1/11/202417/6/2026
Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom Fields Framework: from n/a through 5.9.10.
AnalizadaMedia (4.3)0.51%—Metabox Meta BOX15/4/202417/6/2026
The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.
ModificadaMedia (5.4)0.41%—Metabox Meta BOX5/2/202417/6/2026
The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortcode in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaAlta (7.5)1.4%—Metabox Meta BOX9/8/201917/6/2026
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
ModificadaMedia (6.5)1.7%—Metabox Meta BOX9/8/201917/6/2026
The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.