Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.37% | — | Acfextended Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities… | |
| Aplazada | Alta (8.1) | 0.23% | — | Advancedcustomfields Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a… | |
| Aplazada | Media (5.3) | 0.52% | — | Advancedcustomfields Advanced Custom FieldsAI | 31/5/2026 | 22/7/2026 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and… | |
| Aplazada | Crítica (9.8) | 0.87% | — | Acfextended Advanced Custom Fields ExtendedAI | 28/5/2026 | 21/7/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Media (6.4) | 0.35% | — | Advanced Custom Fields Font AwesomeAI | 15/5/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it… | |
| Aplazada | Media (6.5) | 0.38% | — | Acfextended Advanced Custom Fields ExtendedAI | 12/5/2026 | 30/9/2026 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.86% | — | Advancedcustomfields Advanced Custom FieldsAI | 15/4/2026 | 17/6/2026 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper… | |
| Aplazada | Media (6.4) | 0.30% | — | Advanced Custom Fields Font Awesome FieldAI | 19/2/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Acfextended Advanced Custom Fields ExtendedAI | 20/1/2026 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Crítica (9.8) | 68% | — | Acfextended Advanced Custom Fields ExtendedAI | 3/12/2025 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.20% | — | Tusko Trush Advanced Custom Fields CPT Options PagesAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9. | |
| Aplazada | Media (4.6) | 0.21% | — | Advancedcustomfields Advanced Custom FieldsAI | 8/8/2025 | 17/6/2026 | An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered. | |
| Aplazada | Crítica (10) | 1.8% | — | Advancedcustomfields Advanced Custom FieldsAI | 5/8/2025 | 16/6/2026 | The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include… | |
| Aplazada | Media (4.3) | 0.23% | — | Wpengine INC Advanced Custom Fields PROAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced Custom Fields PRO: from n/a before 6.3.2. | |
| Analizada | Media (6.6) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 15/11/2024 | 17/6/2026 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin… | |
| Aplazada | Media (5.4) | 0.30% | — | Wpengine INC Advanced Custom Fields PROAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1. | |
| Aplazada | Media (4.3) | 0.32% | — | Wpengine Advanced Custom Fields PROAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1. | |
| Aplazada | Media (5.3) | 0.53% | — | Secure Custom FieldsAIAdvancedcustomfields Advanced Custom FieldsAI | 17/10/2024 | 17/6/2026 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF,… | |
| Modificada | Media (6.1) | 0.42% | — | Wpengine Advanced Custom Fields | 4/9/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed… | |
| Modificada | Media (6.5) | 0.43% | — | Advancedcustomfields Advanced Custom Fields | 20/6/2024 | 17/6/2026 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access | |
| Aplazada | Crítica (9.9) | 0.59% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Aplazada | Alta (8.5) | 0.43% | — | Wpengine INC Advanced Custom Fields PROAI | 10/6/2024 | 17/6/2026 | Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10. | |
| Modificada | Media (5.4) | 0.52% | — | Advancedcustomfields Advanced Custom Fields | 5/2/2024 | 17/6/2026 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Modificada | Alta (7.5) | 0.52% | — | Advancedcustomfields Advanced Custom Fields | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2. |