Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.26% | — | WP EditorAI | 1/5/2026 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme… | |
| Analizada | Media (4.9) | 0.53% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information. | |
| Analizada | Alta (7.2) | 1.0% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which… | |
| Aplazada | Media (5.9) | 0.40% | — | Benjamin Chris WP EditormdAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor wp-editormd allows Stored XSS.This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through <= 10.2.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Itpathsolutions Scss WP EditorAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor scss-wp-editor allows Cross Site Request Forgery.This issue affects SCSS WP Editor: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.4) | 0.32% | — | Bootstrap Blocks FOR WP EditorAI | 7/1/2025 | 17/6/2026 | The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Alta (7.2) | 0.58% | — | Benjaminrojas WP Editor | 13/9/2024 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call… | |
| Aplazada | Alta (7.1) | 0.35% | — | Benjaminrojas WP EditorAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Rojas WP Editor allows Reflected XSS.This issue affects WP Editor: from n/a through 1.2.8. | |
| Modificada | Alta (7.5) | 0.45% | — | Benjaminrojas WP Editor | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1.2.7. | |
| Modificada | Alta (7.2) | 0.77% | — | Benjaminrojas WP Editor | 16/1/2024 | 17/6/2026 | The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings. | |
| Modificada | Crítica (9.8) | 2.0% | — | Benjaminrojas WP Editor | 14/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | |
| Modificada | Alta (8.8) | 0.68% | — | Benjaminrojas WP Editor | 14/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.93% | — | WP Editor Project WP Editor | 12/8/2019 | 17/6/2026 | The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. | |
| Modificada | Media (4.8) | 0.82% | — | Iiong WP Editor.md | 4/11/2018 | 17/6/2026 | The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area. | |
| Modificada | Media (6.1) | 0.63% | — | WP Editor.md Project WP Editor.md | 1/6/2017 | 17/6/2026 | The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post. |