Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
–

575 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.56%—Siteorigin Widgets BundleAI2/10/20262/10/2026
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the…
AplazadaMedia (5.8)0.19%—Axelerant Testimonials WidgetAI26/9/202628/9/2026
The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
AplazadaAlta (7.5)0.21%—Axelerant Testimonials WidgetAI26/9/202628/9/2026
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
AplazadaMedia (6.8)0.43%—Custom Menu Wizard WidgetAI12/9/202614/9/2026
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
AplazadaAlta (7.5)0.30%—Gingerplugins Sticky Chat WidgetAI11/9/202611/9/2026
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to…
AplazadaAlta (7.5)0.42%—Siteleads Lead Generation Contact Widget AND AI ChatbotAI24/8/202626/8/2026
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
AplazadaMedia (6.9)0.58%—JqwidgetsAI24/8/202627/8/2026
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was…
AplazadaCrítica (9.3)0.40%—Gingerplugins Sticky Chat WidgetAI18/8/202620/8/2026
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
AplazadaMedia (6.5)0.22%—WP TAB WidgetAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
AplazadaAlta (7.5)0.39%—Online Contact WidgetAI18/8/202620/8/2026
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
AplazadaMedia (6.5)0.43%—Chatwoot Chat WidgetAI4/8/202626/8/2026
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload…
AplazadaMedia (5.3)0.32%—Simple Google Calendar Outlook Events WidgetAI4/8/202626/8/2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.
AnalizadaMedia (6.5)0.34%—Widgetfactorylimited JCE29/7/20265/8/2026
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise…
AplazadaMedia (4.4)0.40%—Widgets FOR Google ReviewsAI11/7/202613/7/2026
The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to…
AplazadaAlta (8.8)0.95%—Widget Logic VisualAI8/7/20268/7/2026
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the widget-logic-update-conditional-tags AJAX action combined with…
AplazadaMedia (6.4)0.33%—Reviews Widgets FOR Google Yelp AND TripadvisorAI6/7/20267/7/2026
The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()…
AplazadaMedia (4.3)0.39%—Envothemes Templates Widgets FOR Elementor AND WoocommerceAI2/7/20262/7/2026
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a…
AplazadaMedia (6.4)0.26%—Crocoblock Jetwidgets FOR ElementorAI1/7/20261/7/2026
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class…
AplazadaCrítica (9.9)0.79%—Widget OptionsAI25/6/202625/6/2026
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
AplazadaMedia (6.5)0.29%—Marketingfire Widget OptionsAI17/6/20261/10/2026
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.
AplazadaAlta (7.1)0.25%—Product Filter Widget FOR ElementorAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.
AplazadaAlta (7.1)0.18%—Elis Wordcents Adsense Widget With AnalyticsAI15/6/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.
AplazadaMedia (6.9)0.69%—Wordpress Imdb Profile WidgetAI15/6/202617/6/2026
WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.php containing…
AplazadaMedia (6.1)0.21%—Product Filter Widget FOR ElementorAI9/6/202623/7/2026
The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.4)0.49%—Click TO Chat WA WidgetAI6/6/202623/7/2026
The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to insufficient escaping when embedding user-supplied shortcode attribute values inside JavaScript string literals that are…