|
3021
|
8.1 |
HIGH
Network
|
-
|
-
|
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' …
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3022
|
8.1 |
HIGH
Network
|
-
|
-
|
El plugin Importar y exportar usuarios y clientes para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta, e incluyendo, la 1.29.7. Esto se debe a que la función 'save_ext…
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3023
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix WARN_ON in tracing_buffers_mmap_close
When a process forks, the child process copies the parent's VMAs but the
user_…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3024
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
tracing: Corrección de WARN_ON en tracing_buffers_mmap_close
Cuando un proceso hace fork, el proceso hijo copia los VMAs del pad…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3025
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and includin…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3026
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin ElementCamp para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'meta_query[compare]' en la acción AJAX 'tcg_select2_search_post' en todas las versiones has…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3027
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to…
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3028
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Hr Press Lite para WordPress es vulnerable a acceso no autorizado de datos sensibles de empleados debido a una comprobación de capacidad faltante en la acción AJAX 'hrp-fetch-employees' en …
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3029
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3030
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Post Snippits para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.0, inclusive. Esto se debe a la falta de validación de nonce e…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|