Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.20% | — | ALL IN ONE WP Security AND FirewallAI | 30/9/2026 | 30/9/2026 | Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Cloudsecure WP SecurityAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | Vuong Nguyen WP Security MasterAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site Request Forgery.This issue affects WP Security Master: from n/a through <= 1.0.2. | |
| Aplazada | Baja (3.7) | 0.32% | — | ALL IN ONE WP Security AND Firewall Team ALL IN ONE WP Security AND FirewallAI | 4/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4. | |
| Aplazada | Media (4.3) | 0.21% | — | Tipsandtricks-hq ALL IN ONE WP Security & FirewallAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6. | |
| Modificada | Media (4.3) | 0.38% | — | Flippercode Wp-security-questions | 1/7/2023 | 17/6/2026 | The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request… | |
| Modificada | Alta (8.8) | 0.31% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 22/11/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. | |
| Modificada | Media (4.7) | 0.75% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 2/5/2022 | 17/6/2026 | The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as… | |
| Modificada | Media (6.1) | 1.5% | — | Tipsandtricks-hq WP Security & Firewall | 10/2/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. | |
| Modificada | Media (6.1) | 0.93% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. | |
| Modificada | Alta (8.8) | 0.84% | — | Wpsecurityauditlog WP Security Audit LOG | 6/4/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5.3) | 16% | — | Wpsecurityauditlog WP Security Audit LOG | 4/4/2018 | 17/6/2026 | An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information. | |
| Modificada | Media (4.3) | 1.7% | — | Bit51 Better-wp-security | 13/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263. | |
| Modificada | Media (4.3) | 2.1% | — | Bit51 Better-wp-security | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header. |