Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.79% | — | Widget OptionsAI | 25/6/2026 | 25/6/2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. | |
| Aplazada | Media (6.5) | 0.29% | — | Marketingfire Widget OptionsAI | 17/6/2026 | 1/10/2026 | Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1. | |
| Aplazada | Alta (8.8) | 0.77% | — | Widget OptionsAI | 2/5/2026 | 17/6/2026 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic expressions with an… | |
| Aplazada | Crítica (9) | 0.43% | — | Marketing Fire Widget OptionsAI | 5/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Options: from n/a through <= 4.1.3. | |
| Aplazada | Media (6.4) | 0.19% | — | Widget OptionsAI | 25/10/2025 | 17/6/2026 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple functions in all versions up to, and including, 4.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.20% | — | Widget Options ExtendedAI | 23/9/2025 | 17/6/2026 | The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sidebar' shortcode in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.9) | 1.1% | — | Marketing Fire Widget OptionsAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options allows OS Command Injection.This issue affects Widget Options: from n/a through <= 4.1.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Widget OptionsAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.8. | |
| Aplazada | Media (4.3) | 0.34% | — | Marketing Fire Widget OptionsAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.6.1. | |
| Aplazada | Crítica (9.9) | 44% | — | Widget OptionsAI | 28/11/2024 | 17/6/2026 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due to the plugin allowing users to supply input that will be… | |
| Aplazada | Media (6.5) | 0.42% | — | Marketing Fire LLC Widget Options ExtendedAI | 8/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget Options - Extended: from n/a through 5.1.0. |