Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.26%—WP EditorAI1/5/202617/6/2026
The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme…
AnalizadaMedia (4.9)0.53%—Benjaminrojas WP Editor17/4/202517/6/2026
The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information.
AnalizadaAlta (7.2)1.0%—Benjaminrojas WP Editor17/4/202517/6/2026
The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which…
AplazadaMedia (5.9)0.40%—Benjamin Chris WP EditormdAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor wp-editormd allows Stored XSS.This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through <= 10.2.1.
AplazadaMedia (4.3)0.21%—Itpathsolutions Scss WP EditorAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor scss-wp-editor allows Cross Site Request Forgery.This issue affects SCSS WP Editor: from n/a through <= 1.2.1.
AplazadaMedia (6.4)0.32%—Bootstrap Blocks FOR WP EditorAI7/1/202517/6/2026
The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AnalizadaAlta (7.2)0.58%—Benjaminrojas WP Editor13/9/202417/6/2026
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call…
AplazadaAlta (7.1)0.35%—Benjaminrojas WP EditorAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Rojas WP Editor allows Reflected XSS.This issue affects WP Editor: from n/a through 1.2.8.
ModificadaAlta (7.5)0.45%—Benjaminrojas WP Editor17/3/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1.2.7.
ModificadaAlta (7.2)0.77%—Benjaminrojas WP Editor16/1/202417/6/2026
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
ModificadaCrítica (9.8)2.0%—Benjaminrojas WP Editor14/8/201917/6/2026
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
ModificadaAlta (8.8)0.68%—Benjaminrojas WP Editor14/8/201917/6/2026
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
ModificadaMedia (6.1)0.93%—WP Editor Project WP Editor12/8/201917/6/2026
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
ModificadaMedia (4.8)0.82%—Iiong WP Editor.md4/11/201817/6/2026
The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.
ModificadaMedia (6.1)0.63%—WP Editor.md Project WP Editor.md1/6/201717/6/2026
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.