Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

188 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.33%—LWS OptimizeAI2/8/202626/8/2026
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
AplazadaAlta (8.1)0.66%—Image OptimizerAI2/7/20262/7/2026
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they…
AplazadaAlta (8.8)1.1%—Offload AI Optimize With Cloudflare ImagesAI18/6/202618/6/2026
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the…
AplazadaAlta (7.2)0.54%—Shortpixel Image OptimizerAI15/6/202617/6/2026
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
AplazadaMedia (4.9)0.34%—Lwsoptimize LWS OptimizeAI13/6/202623/7/2026
The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested from page HTML and converting same-site URLs to…
AplazadaAlta (8.8)0.45%—AutoptimizeAIClearfy CacheAISiteground Speed OptimizerAI18/5/202617/6/2026
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular…
AplazadaAlta (8.1)0.36%—SqloptimizerAI13/5/202617/6/2026
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
AplazadaAlta (8.1)1.2%—Wpoptimize WP OptimizeAI7/5/202617/6/2026
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it…
Pendiente de análisisAlta (7.3)0.15%—HP System OptimizerAI15/4/202617/6/2026
HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.
AplazadaMedia (5.4)0.38%—Updraftplus Wp-optimizeAI10/4/202617/6/2026
The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking…
AplazadaMedia (5.4)0.31%—Shortpixel Image OptimizerAI26/3/202617/6/2026
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the…
Pendiente de análisisAlta (7.8)0.21%—Nvidia Model OptimizerAI24/3/202617/6/2026
NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and…
AplazadaMedia (6.4)0.20%—AutoptimizeAI21/3/202617/6/2026
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags…
AplazadaMedia (6.4)0.25%—AutoptimizeAI21/3/202617/6/2026
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rendered into a `<link>`…
AnalizadaAlta (7.8)0.18%—Dell Optimizer3/3/202617/6/2026
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AplazadaMedia (6.5)0.27%—Arya Dhiratara Optimize More ImagesAI20/2/202617/6/2026
Missing Authorization vulnerability in Arya Dhiratara Optimize More! – Images optimize-more-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimize More! – Images: from n/a through <= 1.1.3.
AplazadaMedia (4.3)0.33%—Elementor Image OptimizerAI19/2/202617/6/2026
Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.
AplazadaAlta (8.7)0.40%—FileoptimizerAI18/2/202617/6/2026
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.
AplazadaMedia (6.4)0.23%—Robin Image OptimizerAI5/2/202617/6/2026
The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.9)0.59%—Shortpixel Image OptimizerAI5/2/202617/6/2026
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers,…
AplazadaMedia (5.3)0.26%—Passionatebrains ADD Expires Headers AND Optimized MinifyAI23/1/202617/6/2026
Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Expires Headers & Optimized Minify: from n/a through <= 3.2.0.
AplazadaMedia (4.3)0.30%—Crush Pics Image OptimizerAI14/1/202617/6/2026
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple functions in all versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with Subscriber-level…
ModificadaAlta (8.1)0.48%—Qodeinteractive Optimize8/1/202630/9/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.
AplazadaAlta (7.1)0.22%—Plugin OptimizerAI29/12/202517/6/2026
Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7.
AplazadaMedia (6.5)0.25%—Anton Vanyukov Offload AI Optimize With Cloudflare ImagesAI18/12/202517/6/2026
Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5.