Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.26% | — | Fatcatapps Easy Pricing TablesAI | 30/9/2026 | 30/9/2026 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | |
| Aplazada | Media (6.1) | 0.36% | — | Pricing Tables FOR WPAI | 12/5/2026 | 17/6/2026 | The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.26% | — | Quanticalabs Css3 Compare Pricing TablesAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Reflected XSS.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6. | |
| Aplazada | Alta (7.1) | 0.21% | — | Quanticalabs Css3 Vertical WEB Pricing TablesAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables allows Reflected XSS.This issue affects CSS3 Vertical Web Pricing Tables: from n/a through <= 1.9. | |
| Aplazada | Media (5.4) | 0.35% | — | Quanticalabs Css3 Compare Pricing TablesAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6. | |
| Analizada | Media (5.4) | 0.25% | — | Webdevocean Pricing Tables | 18/2/2025 | 17/6/2026 | The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Media (5.3) | 0.64% | — | Realwebcare WRC Pricing TablesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Realwebcare WRC Pricing Tables allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WRC Pricing Tables: from n/a through 2.3.7. | |
| Aplazada | Media (6.4) | 0.27% | — | WDO Pricing TablesAI | 27/11/2024 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (6.5) | 0.38% | — | Commonninja Pricer Ninja Pricing TablesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja pricer-ninja-pricing-tables allows Stored XSS.This issue affects Pricer Ninja: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Offshorent Solutions PVT LTD OS Pricing TablesAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd OS Pricing Tables os-pricing-tables allows Stored XSS.This issue affects OS Pricing Tables: from n/a through <= 1.2. | |
| Analizada | Media (5.4) | 0.33% | — | Fatcatapps Easy Pricing Tables | 6/11/2024 | 17/6/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.36% | — | Fatcatapps Easy Pricing TablesAI | 30/10/2024 | 17/6/2026 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.5. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (4.3) | 0.21% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the deletePricingTable() function. This makes it possible for unauthenticated attackers to delete pricing tables via a forged… | |
| Modificada | Media (4.3) | 0.21% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the savePricingTable() function. This makes it possible for unauthenticated attackers to create and edit pricing tables via a… | |
| Modificada | Media (4.8) | 0.33% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (4.8) | 0.37% | — | Realwebcare WRC Pricing Tables | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Realwebcare WRC Pricing Tables plugin <= 2.3.7 versions. | |
| Modificada | Media (6.5) | 0.90% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (5.4) | 0.47% | — | Fatcatapps Pricing Tables | 30/1/2023 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (6.1) | 1.5% | — | Fatcatapps Easy Pricing Tables | 27/6/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.56% | — | Fatcatapps Easy Pricing Tables | 2/6/2022 | 17/6/2026 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress. | |
| Modificada | Media (6.5) | 0.53% | — | Fatcatapps Easy Pricing Tables | 7/3/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion |