Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.26%—MW WP FormAI2/10/20263/10/2026
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (4.8)0.24%—MW WP FormAI1/9/20261/9/2026
The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have…
AplazadaBaja (3.5)0.24%—MW WP FormAI30/8/202631/8/2026
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
AplazadaAlta (7.5)0.51%—Wpforms WP Forms ConnectorAI24/6/202625/6/2026
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the…
AplazadaAlta (7.1)0.25%—MW WP FormAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.
AplazadaMedia (4.4)0.33%—MW WP FormAI10/6/202623/7/2026
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary…
AplazadaMedia (5.3)0.40%—MW WP FormAI14/5/202617/6/2026
The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from…
AplazadaAlta (8.1)0.92%—MW WP FormAI8/4/202624/7/2026
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a function that returns…
AplazadaAlta (8.1)0.91%—MW WP FormAI2/4/202617/6/2026
The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move…
AplazadaMedia (4.3)0.21%—Approveme WP Forms Signature Contract ADD ONAI3/2/202617/6/2026
Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2.
AplazadaMedia (4.3)0.22%—Imran Tauqeer Cubewp FormsAI17/6/202517/6/2026
Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.5.
ModificadaMedia (5.4)0.39%—Wp-formassembly18/2/202517/6/2026
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.37%—Imran Tauqeer Cubewp FormsAI7/1/202517/6/2026
Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.10.
AplazadaMedia (5.3)0.39%—MW WP FormAI2/1/202517/6/2026
Missing Authorization vulnerability in Webの相談所 MW WP Form mw-wp-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MW WP Form: from n/a through <= 4.4.5.
AplazadaAlta (7.1)0.29%—Imran Tauqeer Cubewp FormsAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Stored XSS.This issue affects CubeWP Forms: from n/a through <= 1.1.1.
AplazadaMedia (5.3)0.38%—Nitinrathod WP Forms Puzzle CaptchaAI4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
AplazadaMedia (6.5)0.74%—Wp-formassemblyAI24/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Path Traversal.This issue affects WP-FormAssembly: from n/a through 2.0.5.
AplazadaMedia (6.5)0.31%—Wp-formassemblyAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10.
ModificadaMedia (5.4)0.32%—Web-soudan MW WP Form10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Form allows Stored XSS.This issue affects MW WP Form: from n/a through 5.0.6.
ModificadaCrítica (9.8)1.4%—MW WP Form Project MW WP Form11/1/202417/6/2026
The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make…
ModificadaCrítica (9.8)1.3%—Web-soudan MW WP Form16/12/202317/6/2026
The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the…
ModificadaMedia (6.1)0.21%—Nitinrathod WP Forms Puzzle Captcha30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
ModificadaMedia (5.4)0.40%—Web-dorado WP Form Builder22/11/202317/6/2026
The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder' shortcode in versions up to, and including, 1.0.72 due to insufficient input sanitization and output escaping on 'id' user supplied attribute. This makes it possible for authenticated attackers…
ModificadaAlta (8.8)0.21%—Nitinrathod WP Forms Puzzle Captcha11/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1 versions.
ModificadaCrítica (9.8)1.2%—MW WP Form Project MW WP Form23/5/202317/6/2026
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.