Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.5)0.19%—WP 2FAAI3/10/20263/10/2026
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
AplazadaMedia (6.4)0.28%—WP 2FAAI14/7/202614/7/2026
The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.
AplazadaMedia (6.3)0.21%—WP 2FAAI24/11/202517/6/2026
The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them
AnalizadaAlta (7.5)0.40%—Dueclic WP 2FA With Telegram15/10/202417/6/2026
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
AnalizadaAlta (8.8)0.48%—Dueclic WP 2FA With Telegram15/10/202417/6/2026
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
ModificadaAlta (7.5)0.44%—Melapress WP 2FA21/6/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a through 2.6.3.
ModificadaMedia (6.1)0.41%—Melapress WP 2FA18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA wp-2fa.This issue affects WP 2FA: from n/a through <= 2.6.2.
ModificadaMedia (5.3)0.48%—Melapress WP 2FA21/3/202417/6/2026
Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.
ModificadaMedia (4.3)0.25%—Melapress WP 2FA11/1/202417/6/2026
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the send_backup_codes_email function. This makes it possible for unauthenticated attackers to send…
ModificadaMedia (4.3)0.47%—Wpwhitesecurity WP 2FA11/1/202417/6/2026
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user controlled key. This makes it possible for subscriber-level attackers to email…
ModificadaMedia (5.9)0.83%—Wpwhitesecurity WP 2FA10/10/202217/6/2026
The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
ModificadaMedia (6.1)0.85%—Wpwhitesecurity WP 2FA30/5/202217/6/2026
The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting