Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 308 respecto a la semana anterior
Críticas / altas1351▲ 88 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Slider PROAI | 6/10/2026 | 6/10/2026 | The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions… | |
| Aplazada | Media (6.5) | 0.21% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to… | |
| Aplazada | Alta (8) | 0.23% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are… | |
| Aplazada | Alta (8) | 0.23% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public… | |
| Aplazada | Alta (7.1) | 0.25% | — | Slider PROAI | 23/7/2026 | 23/7/2026 | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | WP Review Slider PROAI | 2/7/2026 | 2/7/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but… | |
| Aplazada | Alta (8.1) | 0.82% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function,… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which… | |
| Aplazada | Crítica (10) | 2.0% | — | Shapedplugin LLC Product Slider PRO FOR WoocommerceAI | 5/6/2026 | 23/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Lambertgroup Accordion Slider PROAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro allows Reflected XSS.This issue affects Accordion Slider PRO: from n/a through <= 1.2. | |
| Aplazada | Alta (8.5) | 0.31% | — | Lambertgroup Accordion Slider PROAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro allows Blind SQL Injection.This issue affects Accordion Slider PRO: from n/a through <= 1.2. | |
| Analizada | Media (6.5) | 0.26% | — | Averta Master Slider PRO | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in averta Master Slider Pro masterslider allows DOM-Based XSS.This issue affects Master Slider Pro: from n/a through <= 3.7.12. | |
| Aplazada | Media (6.5) | 0.26% | — | Binarycarpenter WOO Slider PROAI | 30/5/2025 | 17/6/2026 | The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12. This makes it possible for authenticated attackers,… | |
| Modificada | Media (4.3) | 0.24% | — | Binarycarpenter WOO Slider PRO | 30/5/2025 | 17/6/2026 | Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through <= 1.12. | |
| Analizada | Baja (3.8) | 0.34% | — | Crelly Slider Project Crelly Slider | 27/1/2025 | 17/6/2026 | The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.34% | — | Slider PRO LiteAI | 7/1/2025 | 17/6/2026 | The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.48% | — | Bqworks Slider PROAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6. | |
| Analizada | Media (5.4) | 0.43% | — | Crelly Slider Project Crelly Slider | 6/5/2024 | 17/6/2026 | The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.3) | 0.41% | — | Crelly Slider Project Crelly Slider | 29/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5. | |
| Modificada | Crítica (9.8) | 0.39% | — | Averta Master Slider PRO | 20/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5. | |
| Modificada | Media (6.1) | 0.38% | — | Recent Posts Slider Project Recent Posts Slider | 25/7/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Recent Posts Slider Project Recent Posts Slider | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions. | |
| Modificada | Media (5.4) | 0.55% | — | Promotion Slider Project Promotion Slider | 15/6/2022 | 17/6/2026 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin <= 3.3.4 at WordPress. | |
| Modificada | Baja (2.7) | 0.80% | — | Logo Slider Project Logo Slider | 8/6/2022 | 17/6/2026 | The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection |