Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 392 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Media (5.3) | 0.16% | — | Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated… | |
| Aplazada | Alta (7.2) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (5.3) | 0.20% | — | Peprodev Ultimate InvoiceAI | 25/3/2026 | 17/6/2026 | The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII. | |
| Analizada | Media (4.3) | 0.25% | — | Defenseunicorns Pepr | 16/1/2026 | 17/6/2026 | Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create… | |
| Aplazada | Media (6.4) | 0.24% | — | DpepressAI | 21/5/2025 | 17/6/2026 | The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.38% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'valid_email' value based solely on a supplied username parameter, without verifying that the requester is associated with that user… | |
| Aplazada | Alta (8.2) | 0.45% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata which can be leveraged… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Peprodev Ultimate Profile SolutionsAI | 7/5/2025 | 17/6/2026 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to 7.5.2. This is due to handel_ajax_req() function not having proper restrictions on the change_user_meta functionality that makes it possible to set a OTP code and subsequently log in with that OTP… | |
| Aplazada | Alta (7.1) | 0.29% | — | Pepro DEV Group Pepro CF7 DatabaseAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev CF7 Database pepro-cf7-database allows Stored XSS.This issue affects PeproDev CF7 Database: from n/a through <= 2.0.0. | |
| Modificada | Media (5.3) | 0.48% | — | Peprodev Ultimate Invoice | 19/2/2025 | 17/6/2026 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which… | |
| Aplazada | Alta (7.1) | 0.28% | — | Pepro DEV Group Pepro Bacs Receipt Upload FOR WoocommerceAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev WooCommerce Receipt Uploader pepro-bacs-receipt-upload-for-woocommerce allows Reflected XSS.This issue affects PeproDev WooCommerce Receipt Uploader: from n/a through <= 2.6.9. | |
| Aplazada | Media (6.4) | 0.43% | — | Recipepress ReloadedAI | 21/11/2024 | 17/6/2026 | The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.1) | 0.48% | — | Peprodev Woocommerce Receipt UploaderAI | 16/11/2024 | 17/6/2026 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.5) | 0.27% | — | Pepro DEV Group Pepro Ultimate InvoiceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice pepro-ultimate-invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through <= 2.0.6. | |
| Aplazada | Media (4.3) | 0.20% | — | Peprodev CF7 DatabaseAI | 18/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF7 Database: from n/a through 1.8.0. | |
| Aplazada | Media (5.3) | 0.38% | — | Peprodev Ultimate InvoiceAI | 17/4/2024 | 12/8/2026 | Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0. | |
| Modificada | Alta (7.5) | 0.45% | — | Peprodev Ultimate Invoice | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7. | |
| Modificada | Media (6.1) | 0.38% | — | Peprodev CF7 Database | 25/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions. | |
| Modificada | Media (5.4) | 1.1% | — | Shapepress WP Dsgvo Tools | 29/8/2019 | 17/6/2026 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS. |