Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.5) | 0.19% | — | WP 2FAAI | 3/10/2026 | 3/10/2026 | The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts. | |
| Aplazada | Media (6.4) | 0.28% | — | WP 2FAAI | 14/7/2026 | 14/7/2026 | The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account. | |
| Aplazada | Media (6.3) | 0.21% | — | WP 2FAAI | 24/11/2025 | 17/6/2026 | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them | |
| Analizada | Alta (7.5) | 0.40% | — | Dueclic WP 2FA With Telegram | 15/10/2024 | 17/6/2026 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication. | |
| Analizada | Alta (8.8) | 0.48% | — | Dueclic WP 2FA With Telegram | 15/10/2024 | 17/6/2026 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Alta (7.5) | 0.44% | — | Melapress WP 2FA | 21/6/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3. | |
| Modificada | Media (6.1) | 0.41% | — | Melapress WP 2FA | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2FA: from n/a through <= 2.6.2. | |
| Modificada | Media (5.3) | 0.48% | — | Melapress WP 2FA | 21/3/2024 | 17/6/2026 | Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0. | |
| Modificada | Media (4.3) | 0.25% | — | Melapress WP 2FA | 11/1/2024 | 17/6/2026 | The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the send_backup_codes_email function. This makes it possible for unauthenticated attackers to send… | |
| Modificada | Media (4.3) | 0.47% | — | Wpwhitesecurity WP 2FA | 11/1/2024 | 17/6/2026 | The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user controlled key. This makes it possible for subscriber-level attackers to email… | |
| Modificada | Media (5.9) | 0.83% | — | Wpwhitesecurity WP 2FA | 10/10/2022 | 17/6/2026 | The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared. | |
| Modificada | Media (6.1) | 0.85% | — | Wpwhitesecurity WP 2FA | 30/5/2022 | 17/6/2026 | The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |