Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.35% | — | Supsystic Pricing TableAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12. | |
| Modificada | Media (4.3) | 0.21% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the deletePricingTable() function. This makes it possible for unauthenticated attackers to delete pricing tables via a forged… | |
| Modificada | Media (4.3) | 0.21% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the savePricingTable() function. This makes it possible for unauthenticated attackers to create and edit pricing tables via a… | |
| Modificada | Media (4.8) | 0.33% | — | Svs-websoft SVS Pricing Tables | 2/5/2024 | 17/6/2026 | The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Analizada | Media (5.4) | 0.40% | — | Wpdarko Responsive Pricing Table | 18/3/2024 | 17/6/2026 | The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.44% | — | Wpdarko Responsive Pricing Table | 6/11/2023 | 17/6/2026 | The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.37% | — | Realwebcare WRC Pricing Tables | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Realwebcare WRC Pricing Tables plugin <= 2.3.7 versions. | |
| Modificada | Alta (7.2) | 3.2% | — | Wpdevart Pricing Table Builder | 5/6/2023 | 17/6/2026 | The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins. | |
| Modificada | Media (6.5) | 0.90% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (5.4) | 0.49% | — | Wpdarko Responsive Pricing Table | 28/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Fatcatapps Pricing Tables | 30/1/2023 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (6.1) | 1.5% | — | Fatcatapps Easy Pricing Tables | 27/6/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.56% | — | Fatcatapps Easy Pricing Tables | 2/6/2022 | 17/6/2026 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress. | |
| Modificada | Crítica (9.8) | 13% | — | Reputeinfosystems Pricing Table | 16/5/2022 | 17/6/2026 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users | |
| Modificada | Media (4.8) | 0.60% | — | W3eden Pricing Table | 11/4/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2 | |
| Modificada | Media (6.1) | 0.87% | — | Wpdevart Pricing Table Builder | 21/3/2022 | 17/6/2026 | The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.5) | 0.53% | — | Fatcatapps Easy Pricing Tables | 7/3/2022 | 17/6/2026 | The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 0.90% | — | Sizmic Plugmatter Pricing Table | 16/8/2021 | 17/6/2026 | The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` parameter in the ~/license.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.32. | |
| Modificada | Alta (7.3) | 1.7% | — | Pricing Table BY Supsystic | 23/3/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table. | |
| Modificada | Alta (8.8) | 0.68% | — | Pricing Table BY Supsystic | 25/2/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. | |
| Modificada | Media (6.1) | 0.92% | — | Pricing Table BY Supsystic | 25/2/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS. |