Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
1968 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | — | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Crítica (10) | — | — | Backupsheep Wordpress Backup PluginAI | 1/10/2026 | 1/10/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wordpress Backup MigrationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Persistent Login Persistent LoginAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary… | |
| Aplazada | Baja (2.7) | 0.19% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending… | |
| Aplazada | Baja (2.7) | 0.17% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by… | |
| Aplazada | Alta (8.8) | 0.14% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator… | |
| Aplazada | Media (6.4) | 0.19% | — | Wordplus Better MessagesAI | 25/9/2026 | 25/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.27% | — | Wordplus Better MessagesAI | 25/9/2026 | 25/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Alta (8.1) | 20% | ⚠ Explotación activa | Wordpress | 22/9/2026 | 28/9/2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | |
| Aplazada | Alta (7.6) | 0.38% | — | Devitems Hashbar Wordpress Notification BARAI | 22/9/2026 | 22/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | |
| Aplazada | Baja (3.7) | 0.24% | — | Tiktok Wordpress PluginAI | 20/9/2026 | 22/9/2026 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Aplazada | Media (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… | |
| Aplazada | Alta (7.2) | 0.50% | — | Photo Gallery Sliders Proofing WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator… | |
| Aplazada | Media (5.3) | 0.62% | — | Wordlift AI Powered SEO SchemaAI | 19/9/2026 | 21/9/2026 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /wordlift/v1/jsonld/ routes (jsonld/{id}, jsonld/http/{item_id},… | |
| Aplazada | Media (6.5) | 0.70% | — | Wordplus Better MessagesAI | 19/9/2026 | 21/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.56% | — | Wordplus Better MessagesAI | 19/9/2026 | 21/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check… | |
| Aplazada | Alta (7.1) | 0.38% | — | WordpressAI | 18/9/2026 | 19/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through… | |
| Aplazada | Alta (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 17/9/2026 | 18/9/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Aplazada | Media (5.3) | 0.27% | — | LoginwordpressAIWwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out… | |
| Aplazada | Alta (7.1) | 0.34% | — | Multivendorx Wordpress PluginAI | 16/9/2026 | 17/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it. |