Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.50%—Wpdownloadmanager WP DownloadmanagerAI5/8/202626/8/2026
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no…
AplazadaMedia (6.5)1.3%—Wpdownloadmanager WP DownloadmanagerAI18/2/202617/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion functionality. This is due to insufficient validation of user-supplied file paths, allowing directory traversal sequences. This makes it possible for…
AplazadaBaja (2.7)0.76%—Wpdownloadmanager Wp-downloadmanagerAI18/2/202617/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix…
AplazadaAlta (7.2)0.66%—Wpdownloadmanager Wp-downloadmanagerAI26/9/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on…
AplazadaAlta (7.1)0.13%—R-win Wp-downloadcounterAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This issue affects WP-DownloadCounter: from n/a through <= 1.01.
AnalizadaAlta (7.2)0.94%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary…
AnalizadaMedia (4.9)0.42%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaAlta (7.1)0.30%—Misanthrop WP Download CodesAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in misanthrop WP Download Codes wp-download-codes allows Reflected XSS.This issue affects WP Download Codes: from n/a through <= 2.5.4.
AplazadaAlta (7.1)0.32%—Lesterchan Wp-downloadmanagerAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through <= 1.68.8.
ModificadaMedia (5.4)0.57%—Wp-downloadmanager Project Wp-downloadmanager25/3/202217/6/2026
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
ModificadaMedia (5.4)0.56%—Wp-downloadmanager Project Wp-downloadmanager18/3/202217/6/2026
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
ModificadaMedia (5.4)0.54%—Wp-downloadmanager Project Wp-downloadmanager18/3/202217/6/2026
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.
ModificadaMedia (5.3)0.93%—Wp-downloadmanager Project Wp-downloadmanager7/7/202117/6/2026
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
ModificadaMedia (6.8)0.95%—Lesterchan Wp-downloadmanager19/4/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaAlta (10)17%💥 ExploitGiulio Ganci WP Downloads ManagerWordpress WP Downloads Manager30/7/200816/6/2026
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in…
ModificadaAlta (7.5)2.7%💥 ExploitArnos Toolbox Wp-downloadWordpress WP Download2/4/200816/6/2026
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
Orbitaley — Vulnerabilidades