87 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2026-1867
Guest posting / Frontend Posting / Front Editor Web Windows
5.9
MEDIUM
EPSS
0.1%
2026 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6's settings, it is possible for an unauthenticated attacker to export and download all of the form data/settings, including the administrator's email address.

CVE-2026-40355
Kerberos 5 Windows
5.9
MEDIUM
EPSS
0.1%
2026 CWE-476 1 PoC

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

CVE-2026-40356
Kerberos 5 Windows
5.9
MEDIUM
EPSS
0.1%
2026 CWE-191 1 PoC

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

CVE-2026-3881
Performance Monitor Web Windows
5.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks

CVE-2026-0829
Frontend File Manager Plugin Web Windows ⚡ nuclei
5.8
MEDIUM
EPSS
2.6%
2026 1 PoC

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

CVE-2026-6867
Wireshark Windows
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-5407
Wireshark Windows
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 2 PoCs

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-5306
Check & Log Email Web Windows
5.4
MEDIUM
EPSS
0.1%
2026 1 PoC

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

CVE-2026-2712
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance Web Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke ad

CVE-2026-0903
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)

CVE-2026-2696
Export All URLs Web Windows
5.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly accessible wp-content/uploads/ directory. As a result, any unauthenticated user can brute-force the filenames to gain access to sensitive data contained within the exported files.

CVE-2026-2343
PeproDev Ultimate Invoice Web Windows
5.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.

CVE-2026-4106
HT Mega Addons for Elementor Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.8%
2026 1 PoC

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days

CVE-2026-5335
Magic Export & Import Web Windows
5.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.

CVE-2026-1890
LeadConnector Web Windows
5.3
MEDIUM
EPSS
0.1%
2026 1 PoC

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

CVE-2026-1969
trx_addons Web Windows
5.3
MEDIUM
EPSS
0.1%
2026 1 PoC

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

CVE-2026-1430
WP Lightbox 2 Web Windows
4.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-1128
WP eCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could allow attackers to make a logged in admin remove them via a CSRF attack

CVE-2026-2687
Reading progressbar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-0929
RegistrationMagic Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.