Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

792 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.19%—Htplugins HT Contact FormAI29/9/202630/9/2026
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.5)0.75%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (6.4)0.33%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaBaja (3.5)0.14%—Pickplugins Post GridAI24/9/202624/9/2026
The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection…
AplazadaMedia (6.5)0.17%—Pickplugins Post GridAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
AplazadaMedia (4.3)0.15%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking…
AplazadaMedia (6.8)0.23%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.
AplazadaMedia (6.5)0.20%—Payment Plugins FOR Paypal WoocommerceAI23/9/202623/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured…
AplazadaAlta (8.8)0.58%—Wpcloudplugins USE Your DriveAIWpcloudplugins OUT OF THE BOXAIWpcloudplugins Share ONE DriveAIWpcloudplugins Lets BOXAI18/9/202621/9/2026
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users…
AplazadaMedia (5.3)0.34%—Wpplugins Hide MY WP GhostAI18/9/202618/9/2026
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing…
AplazadaMedia (5.3)0.34%—Wpplugins Hide MY WP GhostAI18/9/202618/9/2026
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated…
AplazadaMedia (5.3)0.42%—Really-simple-plugins Really Simple SecurityAI18/9/202618/9/2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
AplazadaAlta (7.6)0.38%—Weplugins WP MapsAI17/9/202617/9/2026
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
AplazadaBaja (2.3)0.36%—Really-simple-plugins Really Simple SecurityAI14/9/202619/9/2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a…
AplazadaAlta (7.5)0.34%—Really-simple-plugins Really Simple SecurityAI13/9/202614/9/2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
AplazadaAlta (7.5)0.30%—Gingerplugins Sticky Chat WidgetAI11/9/202611/9/2026
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to…
Pendiente de análisisMedia (4.4)0.18%—Gstreamer Gst-plugins-goodAI11/9/202616/9/2026
A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes,…
AplazadaMedia (5.9)0.23%—Paymentplugins Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires…
AplazadaMedia (5.3)0.34%—Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and…
AplazadaMedia (5.3)0.34%—Paymentpluginsforstripe Payment Plugins FOR StripeAI9/9/20269/9/2026
The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by…
AplazadaAlta (7.1)0.25%—100plugins Open User MAPAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
AplazadaAlta (7.2)0.27%—Wpplugins Hide MY WP GhostAI8/9/20268/9/2026
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
AplazadaAlta (7.5)0.21%—Verygoodplugins WP FusionAI7/9/20268/9/2026
The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)0.45%—Pickplugins ComboblocksAI5/9/20268/9/2026
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,…
AplazadaMedia (6.4)0.42%—Fooplugins FoogalleryAI5/9/20268/9/2026
The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…