Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.14% | — | Emarketdesign Request A QuoteAI | 2/10/2026 | 2/10/2026 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Afrfq Request A Quote FOR WoocommerceAI | 26/9/2026 | 28/9/2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied… | |
| Aplazada | Media (6.5) | 0.28% | — | Yith Woocommerce Request A QuoteAI | 23/9/2026 | 23/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1. | |
| Aplazada | Alta (8.6) | 0.40% | — | Elex Woocommerce Request A QuoteAI | 9/9/2026 | 9/9/2026 | The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Yith Request A Quote FOR WoocommerceAI | 3/9/2026 | 7/9/2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | |
| Aplazada | Alta (7.5) | 0.56% | — | Emarketdesign Request A QuoteAI | 2/7/2026 | 2/7/2026 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the… | |
| Aplazada | Media (6.4) | 0.34% | — | Dealia Request A QuoteAI | 19/2/2026 | 17/6/2026 | The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.8. This is due to the use of `wp_kses()` for output escaping within HTML attribute contexts where `esc_attr()` is required. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Dealia Request A QuoteAI | 19/2/2026 | 17/6/2026 | The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple AJAX handlers in all versions up to, and including, 1.0.7. The admin nonce (DEALIA_ADMIN_NONCE) is exposed to all users with edit_posts capability (Contributor+) via… | |
| Aplazada | Media (5.3) | 0.22% | — | Yithemes Yith Woocommerce Request A QuoteAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in YITHEMES YITH WooCommerce Request A Quote yith-woocommerce-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Request A Quote: from n/a through <= 2.46.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Emarketdesign Request A QuoteAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Emarketdesign Request A QuoteAI | 23/9/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue affects Request a Quote: from n/a through <= 2.5.0. | |
| Aplazada | Media (4.3) | 0.31% | — | Elextensions Elex Woocommerce Request A QuoteAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in ELEXtensions ELEX WooCommerce Request a Quote elex-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WooCommerce Request a Quote: from n/a through <= 2.3.9. | |
| Aplazada | Alta (7.3) | 0.76% | — | Request A Quote FOR Woocommerce AND ElementorAI | 23/11/2024 | 17/6/2026 | The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to… | |
| Analizada | Media (5.9) | 0.37% | — | Emarketdesign Request A Quote | 23/7/2024 | 17/6/2026 | The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 1.4% | — | Emarketdesign Request A Quote | 25/7/2022 | 17/6/2026 | The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it | |
| Modificada | Media (4.8) | 0.64% | — | Emarketdesign Request A Quote | 25/7/2022 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.64% | — | Emarketdesign Request A Quote | 25/10/2021 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.62% | — | Emarketdesign Request A Quote | 12/7/2021 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. |