Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Themeeditor Theme EditorAI | 1/8/2026 | 29/9/2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Mndpsingh287 Theme EditorAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2. | |
| Aplazada | Alta (8.8) | 0.58% | — | Elastic Theme EditorAI | 11/11/2025 | 17/6/2026 | The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files… | |
| Aplazada | Alta (8.8) | 0.40% | — | Themeeditor Theme EditorAI | 18/10/2025 | 25/9/2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request… | |
| Analizada | Alta (7.2) | 0.74% | — | Themeeditor Theme Editor | 29/8/2024 | 17/6/2026 | The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary… | |
| Aplazada | Alta (7.2) | 0.60% | — | Mndpsingh287 Theme EditorAI | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1. | |
| Modificada | Media (4.9) | 1.1% | — | Themeeditor Theme Editor | 5/4/2021 | 17/6/2026 | The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd |