Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.19% | — | WP Oauth ServerAI | 23/9/2026 | 24/9/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and… | |
| Aplazada | Alta (7.5) | 0.26% | — | WP Oauth ServerAI | 27/8/2026 | 28/8/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Oauth ServerAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-oauth WP Oauth Server | 10/4/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3. | |
| Modificada | Media (6.5) | 0.33% | — | Wp-oauth WP Oauth Server | 5/12/2022 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID | |
| Modificada | Media (4.8) | 0.49% | — | Wp-oauth WP Oauth Server | 5/12/2022 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 1.3% | — | Miniorange WP Oauth Server | 22/8/2022 | 17/6/2026 | Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. |