Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.24% | — | Tiktok Wordpress PluginAI | 20/9/2026 | 22/9/2026 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that… | |
| Aplazada | Alta (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 17/9/2026 | 18/9/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Aplazada | Alta (7.1) | 0.34% | — | Multivendorx Wordpress PluginAI | 16/9/2026 | 17/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it. | |
| Aplazada | Alta (7.2) | 0.46% | — | Multivendorx Wordpress PluginAI | 11/9/2026 | 11/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Alta (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 2/9/2026 | 3/9/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Aplazada | Media (4.2) | 0.12% | — | Litextension Wordpress PluginAI | 21/8/2026 | 26/8/2026 | The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF). | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Media (5.4) | 0.14% | — | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Alta (8.1) | 0.38% | — | Shibboleth Wordpress PluginAI | 15/7/2026 | 15/7/2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Plugins WP DebuggingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Alta (8.6) | 1.7% | — | Team Wordpress PluginAI | 5/1/2026 | 17/6/2026 | The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Analizada | Media (6.3) | 0.16% | — | Felixker Wordpress/plugin Upgrade Time OUT Plugin | 9/4/2025 | 17/6/2026 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Media (6.5) | 0.23% | — | Upcasted AWS S3 FOR Wordpress PluginAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 for WordPress Plugin – Upcasted upcasted-s3-offload allows Stored XSS.This issue affects AWS S3 for WordPress Plugin – Upcasted: from n/a through <= 3.0.3. | |
| Analizada | Media (6.5) | 0.20% | — | Kimhuebel Blogintroduction-wordpress-plugin | 12/9/2024 | 17/6/2026 | The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.43% | — | Accesspressthemes Frontend Post Wordpress Plugin | 5/6/2023 | 17/6/2026 | The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain. | |
| Modificada | Alta (7.5) | 0.80% | — | Getaawp Amazon Affiliate Wordpress Plugin | 30/1/2023 | 17/6/2026 | The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies. | |
| Modificada | Media (4.3) | 1.6% | — | Yahoo! Updates FOR Wordpress Plugin Project Yahoo! Updates FOR Wordpress Plugin | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter. | |
| Modificada | Media (6.8) | 37% | — | TOM Willmot Backupwordpress Plugin | 3/11/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other… | |
| Modificada | Media (4.3) | 5.1% | — | Wp-feedstats Wordpress Plugin | 31/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string. |