87 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2026-4267
Query Monitor Web Windows
7.2
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2026-3231
Checkout Field Editor (Checkout Manager) for WooCommerce Web Windows
7.2
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the `prepare_single_field_data()` method in `class-thwcfd-block-order-data.php` first escaping values with `esc_html()` then immediately reversing the escaping with `html_entity_decode()` for radio and checkboxgroup field types, combined with a permissive `wp_kses()` allowlist in `get_allowed_html()` that

CVE-2026-1540
Spam Protect for Contact Form 7 Web Windows
7.2
HIGH
EPSS
0.1%
2026 1 PoC

The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

CVE-2026-2466
DukaPress Web Windows
7.1
HIGH
EPSS
0.0%
2026 1 PoC

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2026-21253
Windows 10 Version 1607 Windows
7.0
HIGH
EPSS
0.1%
2026 CWE-416 2 PoCs

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

CVE-2026-1753
Gutena Forms Web Windows
6.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

CVE-2026-0722
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2026-20872
Windows 10 Version 1607 Windows
6.5
MEDIUM
EPSS
0.1%
2026 CWE-73 2 PoCs

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-3098
Smart Slider 3 Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2026-1900
Link Whisper Free Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

CVE-2026-4079
SQL Chart Builder Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

CVE-2026-4432
YITH WooCommerce Wishlist Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible for unauthenticated attackers to rename any wishlist belonging to any user on the site.

CVE-2026-1710
WooPayments: Integrated WooCommerce Payments Web Windows
6.5
MEDIUM
EPSS
0.1%
2026 CWE-285 1 PoC

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.

CVE-2026-5337
Frontend File Manager Plugin Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 2 PoCs

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, in

CVE-2026-1542
Super Stage WP Web Windows
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2026-1235
WP eCommerce Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2026-0738
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-0737
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-21525
🔥 KEV Windows 10 Version 1607 Windows
6.2
MEDIUM
EPSS
9.4%
2026 CWE-476 2 PoCs

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2026-0561
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Windows
6.1
MEDIUM
EPSS
0.1%
2026 CWE-79 1 PoC

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.