Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.58%—Wptravelengine WP Travel EngineAI22/9/202622/9/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…
AplazadaAlta (7.3)0.40%—Wensolutions WP TravelAI10/9/202621/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.
AplazadaMedia (5.3)0.22%—Wensolutions WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking.
AplazadaBaja (3.7)0.19%—Wptravelengine WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.
AplazadaBaja (3.7)0.19%—Wensolutions WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state…
AplazadaAlta (7.5)0.69%—Wptravelengine WP Travel EngineAI16/8/202620/8/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.32%—Wptravelengine WP Travel EngineAI12/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information,…
AplazadaMedia (5.3)0.16%—Wptravelengine WP Travel EngineAI6/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using…
AplazadaMedia (4.3)0.27%—Wensolutions WP TravelAI30/7/202630/7/2026
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.
AplazadaMedia (5.3)0.30%—Wensolutions WP TravelAI30/7/202630/7/2026
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen…
AplazadaAlta (7.5)0.36%—Wptravelengine WP Travel EngineAI30/7/202630/7/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the…
AplazadaMedia (5.3)0.30%—Wensolutions WP TravelAI20/7/202620/7/2026
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
AplazadaMedia (4.6)0.24%—Wptravelengine WP Travel EngineAI7/7/20269/7/2026
The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image…
AplazadaCrítica (9.3)0.40%—WP Travel Gutenberg BlocksAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.
AplazadaCrítica (9.8)0.56%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
AplazadaAlta (7.5)0.37%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
AplazadaCrítica (9.1)0.46%—WP Travel PROAI29/5/202621/7/2026
The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing…
AplazadaAlta (7.7)0.36%—Wensolutions WP TravelAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through <= 11.4.0.
AplazadaMedia (6.4)0.16%—Wptravelengine WP Travel EngineAI4/4/202624/7/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
AplazadaMedia (5.3)0.25%—Wensolutions WP TravelAI23/1/202617/6/2026
Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 11.1.0.
AplazadaMedia (6.5)0.18%—WP Travel Gutenberg BlocksAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel Gutenberg Blocks wp-travel-blocks.This issue affects WP Travel Gutenberg Blocks: from n/a through <= 3.9.2.
AplazadaCrítica (9.8)0.80%—Wptravelengine WP Travel EngineAI9/10/202517/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the…
AplazadaCrítica (9.8)0.92%—Wptravelengine WP Travel EngineAI9/10/202517/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.17%—Wptravelengine WP Travel EngineAIWptravelengine WTE Elementor WidgetsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine wte-elementor-widgets allows Stored XSS.This issue affects WP Travel Engine: from n/a through <= 1.4.2.
AplazadaAlta (8.1)0.53%—WP Travel Gutenberg BlocksAI20/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel WP Travel Gutenberg Blocks wp-travel-blocks allows PHP Local File Inclusion.This issue affects WP Travel Gutenberg Blocks: from n/a through <= 3.9.0.