Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2561▼ 316 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.33%—WP Gdpr Cookie ConsentAI9/6/202623/7/2026
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the…
AplazadaAlta (7.1)0.12%—Shahjahan Jewel WP Gdpr Cookie ConsentAI6/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
AplazadaMedia (5.4)0.26%—Cookieinformation WP Gdpr ComplianceAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
ModificadaAlta (8.8)1.5%—Cookieinformation Wp-gdpr-compliance5/2/202417/6/2026
The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit…
ModificadaMedia (6.5)0.85%—Appsaloon WP Gdpr7/6/202317/6/2026
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings.
ModificadaMedia (6.1)1.6%—Cookieinformation Wp-gdpr-compliance14/3/202217/6/2026
The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)0.94%—Appsaloon Wp-gdpr31/8/202017/6/2026
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
ModificadaCrítica (9.8)88%—Van-ons Wp-gdpr-compliance12/11/201817/6/2026
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.