Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.37%—Acfextended Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities…
AplazadaAlta (8.1)0.23%—Advancedcustomfields Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a…
AplazadaMedia (5.3)0.52%—Advancedcustomfields Advanced Custom FieldsAI31/5/202622/7/2026
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and…
AplazadaCrítica (9.8)0.87%—Acfextended Advanced Custom Fields ExtendedAI28/5/202621/7/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with…
AnalizadaCrítica (9.3)0.38%—Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+427/5/202617/6/2026
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AplazadaMedia (6.4)0.35%—Advanced Custom Fields Font AwesomeAI15/5/202617/6/2026
The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it…
AplazadaMedia (6.5)0.38%—Acfextended Advanced Custom Fields ExtendedAI12/5/202630/9/2026
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for…
AplazadaMedia (5.3)0.86%—Advancedcustomfields Advanced Custom FieldsAI15/4/202617/6/2026
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper…
AplazadaMedia (6.4)0.30%—Advanced Custom Fields Font Awesome FieldAI19/2/202617/6/2026
The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject…
AplazadaCrítica (9.8)1.5%—Acfextended Advanced Custom Fields ExtendedAI20/1/202617/6/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the…
AplazadaCrítica (9.8)68%—Acfextended Advanced Custom Fields ExtendedAI3/12/202517/6/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated…
AplazadaAlta (8.8)0.20%—Tusko Trush Advanced Custom Fields CPT Options PagesAI22/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.
AplazadaMedia (4.6)0.21%—Advancedcustomfields Advanced Custom FieldsAI8/8/202517/6/2026
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
AplazadaCrítica (10)1.8%—Advancedcustomfields Advanced Custom FieldsAI5/8/202516/6/2026
The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include…
AplazadaMedia (4.3)0.23%—Wpengine INC Advanced Custom Fields PROAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced Custom Fields PRO: from n/a before 6.3.2.
AnalizadaMedia (6.6)0.43%—Advancedcustomfields Advanced Custom Fields15/11/202417/6/2026
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin…
AplazadaMedia (5.4)0.30%—Wpengine INC Advanced Custom Fields PROAI1/11/202417/6/2026
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
AplazadaMedia (4.3)0.32%—Wpengine Advanced Custom Fields PROAI1/11/202417/6/2026
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
AplazadaMedia (5.3)0.53%—Secure Custom FieldsAIAdvancedcustomfields Advanced Custom FieldsAI17/10/202417/6/2026
In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF,…
ModificadaMedia (6.1)0.42%—Wpengine Advanced Custom Fields4/9/202417/6/2026
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed…
ModificadaMedia (6.5)0.43%—Advancedcustomfields Advanced Custom Fields20/6/202417/6/2026
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
AplazadaCrítica (9.9)0.59%—Wpengine INC Advanced Custom Fields PROAI10/6/202417/6/2026
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
AplazadaAlta (8.5)0.43%—Wpengine INC Advanced Custom Fields PROAI10/6/202417/6/2026
Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
ModificadaMedia (5.4)0.52%—Advancedcustomfields Advanced Custom Fields5/2/202417/6/2026
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
ModificadaAlta (7.5)0.52%—Advancedcustomfields Advanced Custom Fields8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.