Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.27% | — | Infinitewp ClientAI | 18/9/2026 | 18/9/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on… | |
| Aplazada | Alta (7.6) | 0.38% | — | Revmakx Infinitewp ClientAI | 20/8/2026 | 24/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request. | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Prosolution WP ClientAI | 16/8/2026 | 20/8/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Prosolution WP ClientAI | 16/8/2026 | 20/8/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Aplazada | Media (4.3) | 0.25% | — | Prosolution WP ClientAI | 12/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the… | |
| Aplazada | Media (6.4) | 0.23% | — | Prosolution WP ClientAI | 12/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Prosolution WP ClientAI | 10/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | |
| Aplazada | Alta (8.6) | 0.52% | — | Prosolution WP ClientAI | 10/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the… | |
| Aplazada | Crítica (9.8) | 0.76% | — | Infinitewp ClientAI | 9/8/2026 | 26/8/2026 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Prosolution WP ClientAI | 20/5/2026 | 24/7/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Prosolution WP ClientAI | 8/4/2026 | 25/7/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server… | |
| Analizada | Media (5.3) | 0.65% | — | Revmakx Infinitewp Client | 8/1/2025 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory. | |
| Modificada | Alta (8.8) | 0.24% | — | Switchwp WP Client Reports | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwitchWP WP Client Reports.This issue affects WP Client Reports: from n/a through 1.0.22. | |
| Modificada | Media (5.9) | 0.64% | — | Revmakx Infinitewp Client | 29/2/2024 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited… | |
| Modificada | Media (6.5) | 0.68% | — | Switchwp WP Client Reports | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions. | |
| Modificada | Media (5.3) | 24% | — | Revmakx Infinitewp Client | 15/8/2023 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be… | |
| Modificada | Crítica (9.8) | 1.8% | — | Revmakx Infinitewp Client | 23/7/2022 | 17/6/2026 | A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to… | |
| Modificada | Crítica (9.8) | 88% | — | Revmakx Infinitewp Client | 6/2/2020 | 17/6/2026 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in. |