Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Wpmudev BrandaAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
AplazadaMedia (5.3)0.12%—Wpmudev ForminatorAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated…
AplazadaBaja (3.7)0.15%—Wpmudev Forminator FormsAI23/9/202623/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail…
AplazadaCrítica (9.8)0.43%—Wpmudev Wpmu DEV DashboardAI28/8/202628/8/2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated…
AplazadaMedia (6.6)0.28%—Wpmudev Defender SecurityAI27/8/202628/8/2026
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
AplazadaAlta (7.2)0.35%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.2)0.44%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.6)0.36%—Wpmudev Forminator FormsAI22/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
AplazadaMedia (4.3)0.27%—Wpmudev SmartcrawlAI19/8/202626/8/2026
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
AplazadaMedia (5.3)0.52%—Wpmudev ForminatorAI16/8/202620/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated…
AplazadaCrítica (9.8)0.86%—Wpmudev UpdatesAI12/8/202626/8/2026
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote…
AplazadaAlta (8.1)0.87%—Wpmudev Wpmu DEV DashboardAI6/8/202612/8/2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by…
AplazadaAlta (7.5)0.50%—Wpmudev ForminatorAI13/7/202613/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.
AplazadaAlta (7.1)0.25%—Wpmudev ForminatorAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.
AplazadaCrítica (9.8)0.62%—Wpmudev BrandaAI20/6/202623/6/2026
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's…
AplazadaMedia (5.3)0.29%—Wpmudev HustleAI12/5/202617/6/2026
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
AplazadaAlta (7.5)0.65%—Wpmudev ForminatorAI5/5/202617/6/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path]' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the…
AplazadaAlta (7.6)0.38%—Wpmudev Broken Link CheckerAI8/4/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.
AplazadaMedia (5.3)0.26%—Wpmudev ForminatorAI13/3/202617/6/2026
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2.
AplazadaMedia (5.3)0.23%—Wpmudev HustleAI3/2/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.
AplazadaCrítica (9.8)1.9%—Wpmudev BrandaAI2/1/202617/6/2026
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's…
AplazadaMedia (4.1)0.32%—Wpmudev Smush Image Compression AND OptimizationAI6/11/202517/6/2026
Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.
AplazadaMedia (5.4)0.23%—Wpmudev SmartcrawlAI22/10/202517/6/2026
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/a through <= 3.14.3.
AnalizadaCrítica (9.8)0.73%—Wpmudev Appointments18/10/202517/6/2026
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the…
AplazadaMedia (4.3)0.23%—Wpmudev SmartcrawlAI30/9/202517/6/2026
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_submodule() function in all versions up to, and including, 3.14.3. This makes it possible for authenticated attackers, with Subscriber-level access…