Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
792 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.19% | — | Htplugins HT Contact FormAI | 29/9/2026 | 30/9/2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.75% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Baja (3.5) | 0.14% | — | Pickplugins Post GridAI | 24/9/2026 | 24/9/2026 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection… | |
| Aplazada | Media (6.5) | 0.17% | — | Pickplugins Post GridAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking… | |
| Aplazada | Media (6.8) | 0.23% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control. | |
| Aplazada | Media (6.5) | 0.20% | — | Payment Plugins FOR Paypal WoocommerceAI | 23/9/2026 | 23/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured… | |
| Aplazada | Alta (8.8) | 0.58% | — | Wpcloudplugins USE Your DriveAIWpcloudplugins OUT OF THE BOXAIWpcloudplugins Share ONE DriveAIWpcloudplugins Lets BOXAI | 18/9/2026 | 21/9/2026 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpplugins Hide MY WP GhostAI | 18/9/2026 | 18/9/2026 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpplugins Hide MY WP GhostAI | 18/9/2026 | 18/9/2026 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated… | |
| Aplazada | Media (5.3) | 0.42% | — | Really-simple-plugins Really Simple SecurityAI | 18/9/2026 | 18/9/2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. | |
| Aplazada | Alta (7.6) | 0.38% | — | Weplugins WP MapsAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | |
| Aplazada | Baja (2.3) | 0.36% | — | Really-simple-plugins Really Simple SecurityAI | 14/9/2026 | 19/9/2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a… | |
| Aplazada | Alta (7.5) | 0.34% | — | Really-simple-plugins Really Simple SecurityAI | 13/9/2026 | 14/9/2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Aplazada | Alta (7.5) | 0.30% | — | Gingerplugins Sticky Chat WidgetAI | 11/9/2026 | 11/9/2026 | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to… | |
| Pendiente de análisis | Media (4.4) | 0.18% | — | Gstreamer Gst-plugins-goodAI | 11/9/2026 | 16/9/2026 | A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes,… | |
| Aplazada | Media (5.9) | 0.23% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires… | |
| Aplazada | Media (5.3) | 0.34% | — | Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and… | |
| Aplazada | Media (5.3) | 0.34% | — | Paymentpluginsforstripe Payment Plugins FOR StripeAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by… | |
| Aplazada | Alta (7.1) | 0.25% | — | 100plugins Open User MAPAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Wpplugins Hide MY WP GhostAI | 8/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | |
| Aplazada | Alta (7.5) | 0.21% | — | Verygoodplugins WP FusionAI | 7/9/2026 | 8/9/2026 | The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Pickplugins ComboblocksAI | 5/9/2026 | 8/9/2026 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,… | |
| Aplazada | Media (6.4) | 0.42% | — | Fooplugins FoogalleryAI | 5/9/2026 | 8/9/2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… |