Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.75% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.46% | — | Mapster WP MapsAI | 18/9/2026 | 19/9/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the… | |
| Aplazada | Alta (7.6) | 0.38% | — | Weplugins WP MapsAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Weplugins WP MapsAI | 19/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | |
| Aplazada | Media (6.5) | 0.34% | — | WP Maps PROAI | 9/8/2026 | 26/8/2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary… | |
| Aplazada | Alta (7.5) | 0.48% | — | WP Maps PROAI | 9/8/2026 | 26/8/2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources,… | |
| Aplazada | Media (6.5) | 0.41% | — | Weplugins WP MapsAI | 7/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. | |
| Aplazada | Alta (8.8) | 0.53% | — | Weplugins WP MapsAI | 7/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. | |
| Aplazada | Alta (7.5) | 0.43% | — | Mapster WP MapsAI | 1/8/2026 | 26/8/2026 | The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts. | |
| Aplazada | Media (4.3) | 0.29% | — | Flippercode WP MapsAI | 31/7/2026 | 12/8/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Weplugins WP MapsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | WP Maps PROAI | 15/6/2026 | 23/7/2026 | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access. | |
| Aplazada | Media (4.4) | 0.33% | — | Weplugins WP MapsAI | 6/6/2026 | 23/7/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Crítica (9.8) | 1.9% | — | WP Maps PROAI | 29/5/2026 | 21/7/2026 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which… | |
| Aplazada | Alta (7.5) | 0.47% | — | Weplugins WP MapsAI | 18/5/2026 | 17/6/2026 | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. | |
| Aplazada | Media (6.4) | 0.27% | — | Weplugins WP MapsAI | 16/4/2026 | 30/9/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output escaping on user-supplied… | |
| Aplazada | Alta (7.5) | 0.51% | — | Weplugins WP MapsAI | 23/3/2026 | 17/6/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Alta (7.5) | 0.70% | — | Flippercode WP MapsAI | 11/3/2026 | 17/6/2026 | The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names,… | |
| Aplazada | Alta (8.8) | 0.74% | — | Weplugins WP MapsAI | 17/2/2026 | 17/6/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.6) | 0.37% | — | Flippercode WP MapsAI | 9/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6. | |
| Aplazada | Media (6.4) | 0.26% | — | Mapster WP MapsAI | 26/9/2025 | 17/6/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up to, and including, 1.20.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level permissions and above to inject… | |
| Analizada | Media (4.8) | 0.27% | — | Weplugins WP Maps | 1/5/2025 | 17/6/2026 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.29% | — | Weplugins WP Maps | 1/5/2025 | 17/6/2026 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Weplugins WP Maps | 1/5/2025 | 17/6/2026 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |