Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.31% | — | Feedzy RSS AggregatorAI | 10/8/2026 | 26/8/2026 | The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and… | |
| Aplazada | Media (4.3) | 0.49% | — | Feedzy RSS AggregatorAI | 6/6/2026 | 23/7/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (6.1) | 0.21% | — | RSS AggregatorAI | 7/3/2026 | 17/6/2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's admin-shell.js registering a global message event listener without origin validation… | |
| Aplazada | Alta (7.2) | 0.25% | — | RSS AggregatorAI | 17/2/2026 | 17/6/2026 | The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.4) | 0.26% | — | RSS AggregatorAI | 23/1/2026 | 17/6/2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.1) | 0.20% | — | Broadstreet RSS AggregatorAI | 16/1/2026 | 17/6/2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.8) | 0.26% | — | Feedzy RSS AggregatorAI | 11/12/2025 | 30/9/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web… | |
| Aplazada | Media (5) | 0.29% | — | Feedzy RSS AggregatorAI | 23/10/2025 | 30/9/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.41% | — | Rebelcode RSS Aggregator | 23/10/2024 | 17/6/2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.39% | — | Rebelcode RSS Aggregator | 16/7/2024 | 17/6/2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes it… | |
| Analizada | Media (6.1) | 0.38% | — | Rebelcode RSS Aggregator | 14/5/2024 | 17/6/2026 | The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GET parameter. | |
| Modificada | Media (6.4) | 0.34% | — | Themeisle RSS Aggregator BY Feedzy | 17/4/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor… | |
| Modificada | Media (5.4) | 0.35% | — | Themeisle RSS Aggregator BY Feedzy | 7/4/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type… | |
| Modificada | Media (6.5) | 0.51% | — | Themeisle RSS Aggregator BY Feedzy | 29/2/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. This… | |
| Modificada | Alta (8.8) | 0.71% | — | Themeisle RSS Aggregator BY Feedzy | 29/2/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Modificada | Baja (3.8) | 0.36% | — | Wprssaggregator WP RSS Aggregator | 7/2/2024 | 17/6/2026 | The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations… | |
| Modificada | Media (4.3) | 0.45% | — | Themeisle RSS Aggregator BY Feedzy | 5/2/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.38% | — | Wprssaggregator WP RSS Aggregator | 5/2/2024 | 17/6/2026 | The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Modificada | Media (5.4) | 0.31% | — | Themeisle RSS Aggregator BY Feedzy | 6/1/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Themeisle RSS Aggregator BY Feedzy | 6/1/2024 | 17/6/2026 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers,… | |
| Modificada | Media (4.3) | 0.39% | — | Themeisle RSS Aggregator BY Feedzy | 20/10/2023 | 17/6/2026 | The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged… | |
| Analizada | Media (5.4) | 0.51% | — | Themeisle RSS Aggregator BY Feedzy | 30/1/2023 | 17/6/2026 | The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (6.1) | 2.2% | — | Wprssaggregator WP RSS Aggregator | 28/2/2022 | 17/6/2026 | The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.29% | — | Wprssaggregator WP RSS Aggregator | 27/12/2021 | 17/6/2026 | The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as… | |
| Modificada | Media (4.8) | 0.62% | — | Wprssaggregator WP RSS Aggregator | 29/11/2021 | 17/6/2026 | The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues. |