Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.26% | — | MW WP FormAI | 2/10/2026 | 3/10/2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (4.8) | 0.24% | — | MW WP FormAI | 1/9/2026 | 1/9/2026 | The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have… | |
| Aplazada | Baja (3.5) | 0.24% | — | MW WP FormAI | 30/8/2026 | 31/8/2026 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpforms WP Forms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the… | |
| Aplazada | Alta (7.1) | 0.25% | — | MW WP FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions. | |
| Aplazada | Media (4.4) | 0.33% | — | MW WP FormAI | 10/6/2026 | 23/7/2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.40% | — | MW WP FormAI | 14/5/2026 | 17/6/2026 | The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Alta (8.1) | 0.92% | — | MW WP FormAI | 8/4/2026 | 24/7/2026 | The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a function that returns… | |
| Aplazada | Alta (8.1) | 0.91% | — | MW WP FormAI | 2/4/2026 | 17/6/2026 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move… | |
| Aplazada | Media (4.3) | 0.21% | — | Approveme WP Forms Signature Contract ADD ONAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Imran Tauqeer Cubewp FormsAI | 17/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.5. | |
| Modificada | Media (5.4) | 0.39% | — | Wp-formassembly | 18/2/2025 | 17/6/2026 | The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.37% | — | Imran Tauqeer Cubewp FormsAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.10. | |
| Aplazada | Media (5.3) | 0.39% | — | MW WP FormAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Webの相談所 MW WP Form mw-wp-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MW WP Form: from n/a through <= 4.4.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Imran Tauqeer Cubewp FormsAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Stored XSS.This issue affects CubeWP Forms: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.3) | 0.38% | — | Nitinrathod WP Forms Puzzle CaptchaAI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1. | |
| Aplazada | Media (6.5) | 0.74% | — | Wp-formassemblyAI | 24/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Path Traversal.This issue affects WP-FormAssembly: from n/a through 2.0.5. | |
| Aplazada | Media (6.5) | 0.31% | — | Wp-formassemblyAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10. | |
| Modificada | Media (5.4) | 0.32% | — | Web-soudan MW WP Form | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Form allows Stored XSS.This issue affects MW WP Form: from n/a through 5.0.6. | |
| Modificada | Crítica (9.8) | 1.4% | — | MW WP Form Project MW WP Form | 11/1/2024 | 17/6/2026 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make… | |
| Modificada | Crítica (9.8) | 1.3% | — | Web-soudan MW WP Form | 16/12/2023 | 17/6/2026 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the… | |
| Modificada | Media (6.1) | 0.21% | — | Nitinrathod WP Forms Puzzle Captcha | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1. | |
| Modificada | Media (5.4) | 0.40% | — | Web-dorado WP Form Builder | 22/11/2023 | 17/6/2026 | The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder' shortcode in versions up to, and including, 1.0.72 due to insufficient input sanitization and output escaping on 'id' user supplied attribute. This makes it possible for authenticated attackers… | |
| Modificada | Alta (8.8) | 0.21% | — | Nitinrathod WP Forms Puzzle Captcha | 11/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha plugin <= 4.1 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | MW WP Form Project MW WP Form | 23/5/2023 | 17/6/2026 | Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file. |