Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Getwpfunnels WpfunnelsAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Getwpfunnels WpfunnelsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Getwpfunnels WpfunnelsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | |
| Aplazada | Media (5.3) | 0.42% | — | Getwpfunnels WpfunnelsAI | 9/9/2026 | 9/9/2026 | The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and unauthenticated (wp_ajax_nopriv_) users and the underlying add_offer_product_to_cart() function… | |
| Aplazada | Media (5.3) | 0.30% | — | Getwpfunnels WpfunnelsAI | 4/9/2026 | 8/9/2026 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject. | |
| Aplazada | Media (5.3) | 0.34% | — | Getwpfunnels WpfunnelsAI | 4/9/2026 | 8/9/2026 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled. | |
| Aplazada | Media (5.3) | 0.30% | — | Getwpfunnels WpfunnelsAI | 4/9/2026 | 8/9/2026 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried… | |
| Aplazada | Media (5.3) | 0.18% | — | Getwpfunnels WpfunnelsAI | 4/9/2026 | 8/9/2026 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is… | |
| Aplazada | Media (6.5) | 0.33% | — | Getwpfunnels WpfunnelsAI | 3/9/2026 | 4/9/2026 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | |
| Aplazada | Alta (8.8) | 0.56% | — | Getwpfunnels WpfunnelsAI | 16/7/2026 | 16/7/2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter… | |
| Aplazada | Media (6.6) | 1.2% | — | Getwpfunnels WpfunnelsAI | 9/7/2026 | 9/7/2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Getwpfunnels WpfunnelsAI | 7/7/2026 | 8/7/2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpfunnels PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. | |
| Aplazada | Media (6.4) | 0.20% | — | Getwpfunnels WpfunnelsAI | 4/4/2026 | 24/7/2026 | The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping of the 'button_icon'… | |
| Aplazada | Alta (8.8) | 0.42% | — | Wpfunnels Creator LMSAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18. | |
| Aplazada | Media (5.3) | 0.25% | — | Getwpfunnels WpfunnelsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPFunnels: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.3) | 0.22% | — | Getwpfunnels WpfunnelsAI | 8/11/2025 | 17/6/2026 | The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to… | |
| Aplazada | Media (6.5) | 0.73% | — | Getwpfunnels WpfunnelsAI | 8/11/2025 | 17/6/2026 | The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() function in all versions up to, and including, 3.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files… | |
| Aplazada | Media (6.5) | 0.22% | — | Getwpfunnels WpfunnelsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through <= 3.5.26. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Getwpfunnels WpfunnelsAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18. | |
| Aplazada | Media (6.1) | 0.61% | — | Getwpfunnels WpfunnelsAI | 21/11/2024 | 17/6/2026 | The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Media (4.8) | 0.34% | — | Getwpfunnels Wpfunnels | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6. | |
| Modificada | Media (6.1) | 0.38% | — | Getwpfunnels Wpfunnels | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPress – WPFunnels plugin <= 2.7.16 versions. | |
| Modificada | Media (5.4) | 0.57% | — | Getwpfunnels Drag & Drop Sales Funnel Builder | 6/2/2023 | 17/6/2026 | The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |