Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.35%—Wpeasypay WP EasypayAI3/9/20263/9/2026
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
AplazadaMedia (6.5)0.30%—Wpeasypay WP EasypayAI23/7/202623/7/2026
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
AplazadaMedia (6.5)0.18%—Wpeasypay WP EasypayAI18/6/20261/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.
ModificadaMedia (6.5)0.40%—Wpeasypay WP Easypay24/7/202417/6/2026
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square.
ModificadaMedia (6.1)0.46%—Wpeasypay WP Easypay16/8/202317/6/2026
The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
ModificadaMedia (4.3)0.40%—Wpeasypay WP Easypay12/7/202317/6/2026
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a…
ModificadaAlta (8.8)0.30%—Wpeasypay WP Easypay25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions.