Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

1968 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)——Wordpress File UploadAI1/10/20261/10/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
AplazadaCrítica (10)——Backupsheep Wordpress Backup PluginAI1/10/20261/10/2026
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files…
AplazadaAlta (7.5)0.39%—Wordpress Backup MigrationAI30/9/202630/9/2026
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
AplazadaAlta (7.2)0.54%—Keywordrush Content EGGAI30/9/202630/9/2026
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
AplazadaAlta (7.1)0.25%—Wordpress Persistent Login Persistent LoginAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
AplazadaMedia (6.8)0.24%—Keywordrush Content EGGAI30/9/202630/9/2026
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary…
AplazadaBaja (2.7)0.19%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending…
AplazadaBaja (2.7)0.17%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by…
AplazadaAlta (8.8)0.14%—MCP Server FOR WordpressAI26/9/202628/9/2026
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator…
AplazadaMedia (6.4)0.19%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.5)0.27%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AnalizadaAlta (8.1)20%⚠ Explotación activaWordpress22/9/202628/9/2026
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
AplazadaAlta (7.6)0.38%—Devitems Hashbar Wordpress Notification BARAI22/9/202622/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.
AplazadaBaja (3.7)0.24%—Tiktok Wordpress PluginAI20/9/202622/9/2026
The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
AplazadaMedia (4.2)0.19%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including…
AplazadaAlta (7.2)0.50%—Photo Gallery Sliders Proofing WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator…
AplazadaMedia (5.3)0.62%—Wordlift AI Powered SEO SchemaAI19/9/202621/9/2026
The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /wordlift/v1/jsonld/ routes (jsonld/{id}, jsonld/http/{item_id},…
AplazadaMedia (6.5)0.70%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (5.3)0.56%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check…
AplazadaAlta (7.1)0.38%—WordpressAI18/9/202619/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through…
AplazadaAlta (7.1)0.16%—Dictionary Wordpress Plugin DictionaryAI17/9/202618/9/2026
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
AplazadaMedia (5.3)0.27%—LoginwordpressAIWwbn AvideoAI16/9/202622/9/2026
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out…
AplazadaAlta (7.1)0.34%—Multivendorx Wordpress PluginAI16/9/202617/9/2026
The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it.