Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.67% | — | Miniorange OTP Login Verification SMS NotificationsAI | 26/9/2026 | 28/9/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the… | |
| Aplazada | Media (4.4) | 0.19% | — | OTP Login Register WoocommerceAI | 19/9/2026 | 21/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and… | |
| Aplazada | Media (5.3) | 0.32% | — | OTP Login Register WoocommerceAI | 11/9/2026 | 11/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled… | |
| Aplazada | Crítica (9.1) | 0.42% | — | OTP Login With Phone NumberAI | 5/8/2026 | 26/8/2026 | The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Happy Coders OTP LoginAI | 16/7/2026 | 16/7/2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Miniorange OTP Login Verification AND SMS NotificationsAI | 9/7/2026 | 9/7/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the… | |
| Aplazada | Crítica (9.8) | 0.90% | — | OTP Login With Phone NumberAI | 29/5/2026 | 21/7/2026 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The… | |
| Aplazada | Alta (8.1) | 0.64% | — | OTP Login With Phone Number OTP VerificationAI | 15/8/2025 | 17/6/2026 | The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP… | |
| Modificada | Alta (8.8) | 1.5% | — | Xootix Login/signup PopupXootix OTP Login Woocommerce & Gravity FormsXootix Side Cart WoocommerceXootix Waitlist Woocommerce | 6/6/2024 | 17/6/2026 | Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary… | |
| Modificada | Alta (8.1) | 1.7% | — | Xootix OTP Login Woocommerce & Gravity Forms | 17/5/2023 | 17/6/2026 | The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to… |