Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.8)——Stellarwp THE Events CalendarAI7/10/20267/10/2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
AplazadaMedia (6.5)0.22%—Theeventscalendar THE Events CalendarAI2/10/20262/10/2026
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaMedia (5.4)0.20%—Theeventscalendar THE Events CalendarAI30/9/202630/9/2026
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
AplazadaBaja (3.8)0.23%—Theeventscalendar THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
AplazadaBaja (2.7)0.23%—Modern Tribe THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
AplazadaMedia (5.3)0.25%—Theeventscalendar THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
AplazadaMedia (6.4)0.24%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of…
AplazadaCrítica (9.8)1.4%💥 PoCTheeventscalendar THE Events CalendarAI12/9/202614/9/2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and…
AplazadaCrítica (9.8)1.5%💥 PoCTheeventscalendar THE Events CalendarAI12/9/202614/9/2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse,…
AplazadaAlta (7.2)0.46%—Ameliabooking Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address…
AplazadaMedia (5.3)0.30%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an…
AplazadaBaja (2.7)0.32%—Theeventscalendar THE Events CalendarAI5/9/20268/9/2026
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI2/9/20263/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI29/8/202631/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were…
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AplazadaMedia (5.3)0.47%—Events Calendar Manager Events ManagerAI25/8/202627/8/2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.56%—Theeventscalendar THE Events CalendarAI24/8/202626/8/2026
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
AplazadaCrítica (9.3)0.40%—Webnus Modern Events CalendarAI18/8/202620/8/2026
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
AplazadaBaja (3.7)0.26%—Booking FOR Appointments AND Events CalendarAI13/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (5.3)0.30%—Theeventscalendar THE Events CalendarAI27/7/202627/7/2026
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a…
AplazadaMedia (6.5)0.41%—Roundupwp Registrations FOR THE Events CalendarAI23/7/202623/7/2026
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys…
AplazadaAlta (8.5)0.34%—Theeventscalendar THE Events CalendarAI17/6/20266/10/2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
Orbitaley — Vulnerabilidades