Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.48%—Syncpostwithothersite Sync Post With Other SiteAI18/8/202620/8/2026
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
AplazadaMedia (6.5)0.34%—Syncpostwithothersite Sync Post With Other SiteAI30/7/202630/7/2026
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor)…
AnalizadaMedia (4.3)0.32%—Syncpostwithothersite Sync Post With Other Site3/8/202417/6/2026
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create…
ModificadaMedia (6.1)0.20%—Syncpostwithothersite Sync Post With Other Site15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1.