Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.48%—Syncpostwithothersite Sync Post With Other SiteAI18/8/202620/8/2026
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
AplazadaMedia (6.5)0.34%—Syncpostwithothersite Sync Post With Other SiteAI30/7/202630/7/2026
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor)…
AnalizadaMedia (4.3)0.32%—Syncpostwithothersite Sync Post With Other Site3/8/202417/6/2026
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create…
ModificadaMedia (6.1)0.20%—Syncpostwithothersite Sync Post With Other Site15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1.
ModificadaAlta (7.5)3.6%—Seth Leonard Book OF GuestsSeth Leonard Post IT6/12/200116/6/2026
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.