Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI26/8/202626/8/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
AplazadaMedia (6.4)0.33%—Ibericode Mailchimp FOR WordpressAI22/8/202624/8/2026
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.8)0.79%—Mailgun FOR WordpressAI22/8/202625/8/2026
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through…
AplazadaMedia (4.2)0.12%—Litextension Wordpress PluginAI21/8/202626/8/2026
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).
AplazadaAlta (8.8)0.20%—Devitems Hashbar Wordpress Notification BARAI18/8/202620/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Pendiente de análisisAlta (8.8)1.9%—WordpressAI17/8/20263/9/2026
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has…
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
AplazadaMedia (5.3)0.47%—Prevent Direct Access Protect Wordpress FilesAI13/8/202614/8/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without…
Pendiente de análisisAlta (8.9)0.89%—WordpressAI7/8/20263/9/2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social…
AplazadaAlta (7.1)0.25%—Facebook FOR WordpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
AplazadaCrítica (9.3)0.40%—Wordpress File UploadAI6/8/202612/8/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
AplazadaMedia (6.5)0.27%—Mailgun FOR WordpressAI31/7/202626/8/2026
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's…
AplazadaAlta (7.5)0.41%—Wp-feedstats Wordpress PluginAI31/7/202626/8/2026
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
Pendiente de análisisAlta (8.6)0.25%—Wordpress Coding StandardsAI28/7/20269/9/2026
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as…
AplazadaMedia (6.5)0.22%—Wordpress Social Login AND RegisterAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
AplazadaMedia (5.3)0.30%—Wp-feedstats Wordpress PluginAI22/7/202622/7/2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
AplazadaMedia (5.4)0.14%—Wp-feedstats Wordpress PluginAI20/7/202620/7/2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's…
AnalizadaCrítica (9.8)10%⚠ Explotación activaWordpress17/7/202622/7/2026
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
AnalizadaMedia (5.9)5.9%⚠ Explotación activaWordpress17/7/202629/7/2026
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
AplazadaAlta (8.1)0.38%—Shibboleth Wordpress PluginAI15/7/202615/7/2026
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an…
AplazadaAlta (7.2)0.27%—Wpswings PDF Generator FOR WordpressAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.
AplazadaAlta (7.5)0.48%—Notifications FOR Forms AND Wordpress ActionsAI6/7/20266/7/2026
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
AplazadaAlta (7.1)0.25%—Wordpress Plugins WP DebuggingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.