Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.33% | — | WP Customer AreaAI | 14/7/2026 | 15/7/2026 | The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it… | |
| Aplazada | Alta (8.8) | 0.55% | — | WP Customer AreaAI | 15/6/2026 | 17/6/2026 | Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. | |
| Aplazada | Alta (8.8) | 1.2% | — | WP Customer AreaAI | 17/4/2026 | 17/6/2026 | The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that an administrator grants access to… | |
| Aplazada | Alta (7.5) | 0.43% | — | Aguilatechnologies WP Customer AreaAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Customer Area customer-area allows PHP Local File Inclusion.This issue affects WP Customer Area: from n/a through <= 8.3.5. | |
| Aplazada | Media (4.3) | 0.27% | — | Aguilatechnologies WP Customer AreaAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in aguilatechnologies WP Customer Area customer-area allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Customer Area: from n/a through <= 8.3.4. | |
| Analizada | Media (4.3) | 0.22% | — | Marvinlabs WP Customer Area | 27/1/2025 | 17/6/2026 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Analizada | Media (4.3) | 0.20% | — | Marvinlabs WP Customer Area | 27/1/2025 | 17/6/2026 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack | |
| Modificada | Media (6.1) | 0.47% | — | Marvinlabs WP Customer Area | 24/1/2024 | 17/6/2026 | The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.5) | 0.48% | — | Marvinlabs WP Customer Area | 16/1/2024 | 17/6/2026 | The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address. | |
| Modificada | Media (4.3) | 0.39% | — | Marvinlabs WP Customer Area | 16/1/2024 | 17/6/2026 | The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address. | |
| Modificada | Alta (7.1) | 0.28% | — | Wp-customerarea WP Customer Area | 13/2/2023 | 17/6/2026 | The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example. | |
| Modificada | Media (6.1) | 0.91% | — | Marvinlabs WP Customer Area | 20/8/2019 | 17/6/2026 | The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages. |