Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.62% | — | Zope RestrictedpythonAI | 16/9/2026 | 16/9/2026 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter… | |
| Aplazada | Media (5.3) | 0.35% | — | Dev.institute Restrict User AccessAI | 2/9/2026 | 3/9/2026 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |
| Aplazada | Crítica (9.8) | 0.30% | — | RestrictmateAI | 23/8/2026 | 28/8/2026 | The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover. | |
| Aplazada | Alta (7.5) | 0.69% | — | Page AND Post RestrictionAI | 5/8/2026 | 12/8/2026 | The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards —… | |
| Aplazada | Baja (2.7) | 0.30% | — | Wpchill Simple RestrictAI | 2/8/2026 | 26/8/2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with… | |
| Aplazada | Alta (8.3) | 0.40% | — | Zope RestrictedpythonAI | 8/7/2026 | 10/7/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments,… | |
| Aplazada | Alta (7.5) | 0.30% | — | Premium AGE Verification RestrictionAI | 17/6/2026 | 30/9/2026 | Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Stellarwp Restrict ContentAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/a through <= 3.2.22. | |
| Aplazada | Media (4.3) | 0.34% | — | Restrictcontent Membership Plugin Restrict ContentAI | 20/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users… | |
| Aplazada | Alta (8.1) | 0.35% | — | Membershipupplugin Membership Plugin Restrict ContentAI | 5/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active… | |
| Analizada | Alta (8.1) | 0.16% | — | Innoraft Login Time Restriction | 28/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3. | |
| Analizada | Alta (7.5) | 0.46% | — | Liquidweb Restrict Content | 16/1/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes… | |
| Aplazada | Alta (8.8) | 0.29% | — | Aa-team Premium AGE Verification / Restriction FOR WordpressAIAa-team Responsive Coming Soon Landing Page / Holding Page FOR WordpressAI | 6/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive… | |
| Aplazada | Media (6.4) | 0.24% | — | Membership Plugin Restrict ContentAI | 23/12/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (4.3) | 0.22% | — | Codexpert INC Restrict Elementor WidgetsAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Elementor Widgets, Columns and Sections: from n/a through <= 1.12. | |
| Aplazada | Media (5.3) | 0.27% | — | Restrictions FOR BuddypressAI | 18/11/2025 | 17/6/2026 | The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in all versions up to, and including, 1.5.2. This makes it possible for unauthenticated attackers to opt in and out of tracking. | |
| Aplazada | Alta (7.5) | 0.22% | — | AGE RestrictionAI | 11/11/2025 | 17/6/2026 | The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password. | |
| Aplazada | Media (5.3) | 0.15% | — | Restrict User RegistrationAI | 3/10/2025 | 30/9/2026 | The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the update() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Alta (8.1) | 0.27% | — | Restrict File AccessAI | 15/7/2025 | 17/6/2026 | The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Premium AGE Verification RestrictionAI | 11/7/2025 | 17/6/2026 | The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.62% | — | Restrict File AccessAI | 14/6/2025 | 17/6/2026 | The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Media (6.5) | 0.22% | — | Pluginsandsnippets Simple Page Access Restriction | 30/5/2025 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (8.8) | 0.19% | — | Restrict Route BY IP Project Restrict Route BY IP | 14/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Devrix Restrict User RegistrationAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DevriX Restrict User Registration restrict-user-registration allows Stored XSS.This issue affects Restrict User Registration: from n/a through <= 1.0.1. |