Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.41% | — | Smashballoon Custom Twitter FeedsAI | 18/9/2026 | 18/9/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Alta (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 2/9/2026 | 3/9/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Media (5.4) | 0.14% | 💥 PoC | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Media (5.1) | 0.15% | — | Easy Twitter FeedsAI | 10/6/2026 | 23/7/2026 | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type. | |
| Aplazada | Media (5.4) | 0.32% | — | Smashballoon Feeds FOR YoutubeAI | 18/5/2026 | 17/6/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This… | |
| Aplazada | Alta (7.2) | 0.51% | — | Smashballoon Custom Twitter FeedsAI | 13/5/2026 | 17/6/2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available… | |
| Aplazada | Media (5.4) | 0.32% | — | MY Social FeedsAI | 2/5/2026 | 17/6/2026 | The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce verification in the… | |
| Aplazada | Media (6.4) | 0.19% | — | Twitter FeedsAI | 21/3/2026 | 17/6/2026 | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in the 'TwitterFeeds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.17% | — | Invelity Product FeedsAI | 21/3/2026 | 17/6/2026 | The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated administrator-level attackers to… | |
| Aplazada | Media (5.9) | 0.44% | — | Feeds FOR Youtube PROAI | 17/1/2026 | 17/6/2026 | The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp_submit' AJAX action. This is due to insufficient sanitization of user-supplied data and the use of that data in a file operation. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.25% | — | Syedbalkhi Feeds FOR YoutubeAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Feeds for YouTube: from n/a through <= 2.4.0. | |
| Aplazada | Media (6.4) | 0.22% | — | AI FeedsAI | 12/12/2025 | 7/10/2026 | The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (5.9) | 0.21% | — | Winwar WP Ebay Product FeedsAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Stored XSS.This issue affects WP eBay Product Feeds: from n/a through <= 3.4.9. | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | AI FeedsAI | 25/11/2025 | 17/6/2026 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.0.11. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the… | |
| Aplazada | Media (4.9) | 0.15% | — | Winwar WP Ebay Product FeedsAI | 9/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Server Side Request Forgery.This issue affects WP eBay Product Feeds: from n/a through <= 3.4.8. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Feeds Product Inventory System | 1/9/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Online Feeds Product Inventory System 1.0. This vulnerability affects unknown code of the file /feeds/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.21% | — | WP Filter Combine RSS FeedsAI | 23/8/2025 | 17/6/2026 | The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_listing_page() function in all versions up to, and including, 0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (4.3) | 0.13% | — | Jeff Starr Simple Statistics FOR FeedsAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross Site Request Forgery.This issue affects Simple Statistics for Feeds: from n/a through <= 20250322. | |
| Aplazada | Media (6.5) | 0.24% | — | Wikimedia Mediawiki - Featuredfeeds ExtensionAI | 3/7/2025 | 17/6/2026 | Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FeaturedFeeds Extension: 1.39.X, 1.42.X, 1.43.X. | |
| Aplazada | Media (5.3) | 0.29% | — | Spotlight Social Media FeedsAI | 26/5/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1. | |
| Analizada | Alta (7) | 0.22% | — | Conda-forge MiniforgeConda-forge Openssl-feedstock | 13/5/2025 | 17/6/2026 | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the… |