Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | WP Edit Password ProtectedAI | 2/10/2026 | 2/10/2026 | The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide. | |
| Aplazada | Media (5.3) | 0.21% | — | WP Edit Password ProtectedAI | 2/9/2026 | 3/9/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | |
| Aplazada | Alta (7.5) | 0.44% | — | Wpexperts Password ProtectedAI | 7/8/2026 | 26/8/2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content… | |
| Aplazada | Baja (3.7) | 0.31% | — | Wpexperts Password ProtectedAI | 25/10/2025 | 17/6/2026 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the… | |
| Aplazada | Media (6.1) | 0.22% | — | WP Edit Password ProtectedAI | 11/9/2025 | 17/6/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Analizada | Media (6.5) | 0.32% | — | Passwordprotectwp Password Protect Wordpress | 14/8/2025 | 17/6/2026 | The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API. | |
| Aplazada | Media (5.3) | 0.36% | — | Wpexperts Password ProtectedAI | 17/4/2025 | 17/6/2026 | The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This… | |
| Aplazada | Alta (7.1) | 0.20% | — | Marcucci Password Protect PluginAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored XSS.This issue affects Password Protect Plugin for WordPress: from n/a through <= 0.8.1.0. | |
| Aplazada | Crítica (9.6) | 0.80% | — | Gunghoinc Exclusive Content Password ProtectAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Wpexperts Password ProtectedAI | 15/5/2024 | 17/6/2026 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract… | |
| Modificada | Media (5.3) | 0.57% | — | Rajkakadiya Password Protected Store FOR Woocommerce | 5/3/2024 | 17/6/2026 | The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and content. | |
| Modificada | Media (4.8) | 0.34% | — | Wpexperts Password Protected | 29/2/2024 | 17/6/2026 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Media (5.3) | 0.48% | — | Passwordprotectwp Password Protect Wordpress | 29/2/2024 | 17/6/2026 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts. | |
| Modificada | Media (4.8) | 0.40% | — | Wpexperts Password Protected | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions. | |
| Modificada | Media (5.4) | 0.65% | — | Passwordprotectwp Password Protect Wordpress | 6/2/2023 | 17/6/2026 | The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Alta (7.5) | 2.5% | — | Ascadnetworks Password Protector SD | 8/6/2009 | 16/6/2026 | Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin." | |
| Modificada | Alta (7.5) | 2.8% | — | Wholehogsoftware Password Protect | 10/2/2009 | 16/6/2026 | Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie. | |
| Modificada | Alta (7.5) | 2.1% | — | Wholehogsoftware Password Protect | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 1.3% | — | WEB Animations Password Protect | 31/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | WEB Animations Password Protect | 30/8/2004 | 16/6/2026 | SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp. |