Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.40% | — | AutomatorwpAI | 22/8/2026 | 24/8/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (4.3) | 0.44% | — | AutomatorwpAI | 22/8/2026 | 24/8/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (7.1) | 0.25% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. | |
| Aplazada | Alta (7.6) | 0.27% | — | AutomatorwpAI | 23/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4. | |
| Aplazada | Alta (8) | 0.46% | — | AutomatorwpAI | 9/9/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and including, 5.3.6. This… | |
| Aplazada | Alta (7.2) | 0.40% | — | AutomatorwpAI | 14/6/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Alta (7.6) | 0.34% | — | AutomatorwpAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows Blind SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.1.3. | |
| Aplazada | Crítica (9.6) | 0.74% | — | AutomatorwpAI | 19/12/2024 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output… | |
| Modificada | Media (4.3) | 0.26% | — | Automatorwp | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AutomatorWP plugin <= 2.5.0 leads to object delete. | |
| Modificada | Alta (8.8) | 1.3% | — | Automatorwp | 1/11/2021 | 17/6/2026 | The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions. |