Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | Villatheme Photo Reviews FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | |
| Recibida | Alta (8.1) | 0.34% | — | Photo Reviews FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta… | |
| Recibida | Media (6.4) | 0.30% | — | Rich Showcase FOR Google ReviewsAI | 3/10/2026 | 3/10/2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].text' parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (7.2) | 0.24% | — | Cusrev Customer Reviews FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.5) | 0.30% | — | Photo Reviews FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| Aplazada | Media (5.3) | 0.18% | — | Geminilabs Site ReviewsAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | |
| Aplazada | Alta (7.1) | 0.16% | — | Five Star Restaurant ReviewsAI | 1/10/2026 | 1/10/2026 | The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in… | |
| Aplazada | Alta (7.5) | 0.32% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | |
| Aplazada | Alta (7.1) | 0.20% | — | Geminilabs Site ReviewsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | YayreviewsAI | 30/9/2026 | 30/9/2026 | The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content. | |
| Aplazada | Crítica (9.1) | 0.39% | — | Cusrev Customer Reviews FOR WoocommerceAI | 25/9/2026 | 25/9/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete… | |
| Aplazada | Media (6.1) | 0.33% | — | Gowebsolutions WP Customer ReviewsAI | 19/9/2026 | 21/9/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.1) | 0.45% | — | Geminilabs Site ReviewsAI | 10/9/2026 | 10/9/2026 | The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be… | |
| Aplazada | Alta (8.8) | 0.51% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/8/2026 | 31/8/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Alta (7.2) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 28/8/2026 | 28/8/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review… | |
| Aplazada | Media (6.4) | 0.23% | — | Reviews AND Rating Google ReviewsAI | 26/8/2026 | 27/8/2026 | The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding… | |
| Aplazada | Alta (7.1) | 0.25% | — | Geminilabs Site ReviewsAI | 18/8/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0. | |
| Aplazada | Media (5.4) | 0.23% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin… | |
| Aplazada | Media (6.4) | 0.42% | — | Rich Showcase FOR Google ReviewsAI | 24/7/2026 | 24/7/2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.8) | 0.13% | — | Smashballoon Reviews FeedAI | 20/7/2026 | 21/7/2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the… | |
| Aplazada | Media (6.5) | 0.43% | — | Cusrev Customer Reviews FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist)… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JET ReviewsAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1. | |
| Aplazada | Media (4.4) | 0.40% | — | Widgets FOR Google ReviewsAI | 11/7/2026 | 13/7/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to… | |
| Aplazada | Media (6.4) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.4) | 0.33% | — | Reviews Widgets FOR Google Yelp AND TripadvisorAI | 6/7/2026 | 7/7/2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()… |