Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—Miniorange OTP VerificationAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
AplazadaAlta (7.1)0.25%—Miniorange OTP VerificationAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
AplazadaCrítica (9.8)0.48%—Miniorange OTP VerificationAI27/5/202617/6/2026
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.
AplazadaMedia (5.3)0.26%—Miniorange OTP Verification SMS NotificationAI10/1/202617/6/2026
The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated…
AplazadaCrítica (9.8)0.43%—Orion SMS OTP VerificationAI15/10/202525/9/2026
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to…
AplazadaAlta (8.1)0.37%—Miniorange OTP Verification With FirebaseAI19/9/202517/6/2026
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator.…
AplazadaAlta (8.1)0.64%—OTP Login With Phone Number OTP VerificationAI15/8/202517/6/2026
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP…
AplazadaMedia (4.3)0.34%—Miniorange OTP VerificationAI9/12/202417/6/2026
Missing Authorization vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniorange otp verification: from n/a through <= 4.2.1.
AplazadaCrítica (9.8)0.60%—Miniorange OTP Verification With FirebaseAI17/10/202417/6/2026
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user…
AnalizadaCrítica (9.8)0.60%—Miniorange OTP Verification With Firebase17/10/202417/6/2026
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current…
AnalizadaAlta (8.1)0.63%—Miniorange OTP Verification With Firebase17/10/202417/6/2026
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any…