Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.22%—Popup Maker WPAI2/10/20262/10/2026
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables…
AplazadaMedia (4.3)0.15%—Code-atlantic Popup MakerAI2/10/20262/10/2026
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service…
AplazadaMedia (4.3)0.25%—Omnisend Newsletters Email Marketing SMS AND PopupsAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
AplazadaAlta (7.1)0.18%—Supsystic PopupAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
AplazadaAlta (7.2)0.49%—Code-atlantic Popup MakerAI18/9/202618/9/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.4)0.26%—Code-atlantic Popup MakerAI18/9/202619/9/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.21%—Ashstonestudios Advanced PopupsAI16/9/202616/9/2026
The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to…
AplazadaMedia (5.3)0.31%—Crocoblock JetpopupAI4/9/20264/9/2026
Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.
AplazadaMedia (4.3)0.27%—Brave Popup BuilderAI23/8/202626/8/2026
Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
AplazadaAlta (7.1)0.25%—Brave Popup BuilderAI23/8/202626/8/2026
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
AplazadaCrítica (9.1)0.55%—Popup BY SupsysticAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
AplazadaCrítica (9.8)0.56%—Supsystic PopupAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
AplazadaMedia (6.5)0.22%—Popup BY SupsysticAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
AplazadaAlta (7.1)0.25%—Code-atlantic Popup MakerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
AplazadaAlta (8.8)0.59%—Supsystic Smart PopupAI5/8/202612/8/2026
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method…
AplazadaAlta (7.1)0.13%—Popup FOR CF7 With Sweet AlertAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
AplazadaAlta (7.2)1.2%—Code-atlantic Popup MakerAI9/7/20269/7/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (8.8)0.52%—Themify PopupAI2/7/20262/7/2026
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
AplazadaMedia (5.3)0.33%—Firebox PopupsAI18/6/202618/6/2026
The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV export of all form submissions —…
AplazadaMedia (5.9)0.24%—WP Magnific PopupAI17/6/202617/6/2026
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.
AplazadaAlta (7.1)0.25%—Popup BOXAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
AplazadaMedia (5.1)0.17%—Wordpress Popup BuilderAI4/6/202622/7/2026
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title…
AplazadaMedia (6.1)0.22%—WP Responsive Popup OptinAI22/4/202617/6/2026
The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_referer). This makes…
AplazadaMedia (6.5)0.22%—Hellobar Hello BAR Popup BuilderAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through <= 1.5.1.
AnalizadaMedia (5.4)0.14%—Ays-pro Popup BOX7/4/202630/9/2026
The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups…