Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 316 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.33% | — | WP Gdpr Cookie ConsentAI | 9/6/2026 | 23/7/2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the… | |
| Aplazada | Alta (7.1) | 0.12% | — | Shahjahan Jewel WP Gdpr Cookie ConsentAI | 6/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.4) | 0.26% | — | Cookieinformation WP Gdpr ComplianceAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23. | |
| Modificada | Alta (8.8) | 1.5% | — | Cookieinformation Wp-gdpr-compliance | 5/2/2024 | 17/6/2026 | The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit… | |
| Modificada | Media (6.5) | 0.85% | — | Appsaloon WP Gdpr | 7/6/2023 | 17/6/2026 | The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings. | |
| Modificada | Media (6.1) | 1.6% | — | Cookieinformation Wp-gdpr-compliance | 14/3/2022 | 17/6/2026 | The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.94% | — | Appsaloon Wp-gdpr | 31/8/2020 | 17/6/2026 | controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. | |
| Modificada | Crítica (9.8) | 88% | — | Van-ons Wp-gdpr-compliance | 12/11/2018 | 17/6/2026 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. |