|
2901
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Neos Connector for Fakturama para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 0.0.14 inclusive. Esto se debe a la falta de vali…
|
CWE-352
Origin Validation Error
|
CVE-2026-4143
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2902
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2903
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Games Embed para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode [game] en todas las versiones hasta la 0.1beta inclusive. Esto se debe a una sanitizació…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3996
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2904
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. Thi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2905
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Text Toggle para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'title' del shortcode de los shortcodes [tt_part] y [tt] en todas las versiones hasta la 1.1…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2906
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2907
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Task Manager para WordPress es vulnerable a la ejecución arbitraria de shortcodes a través de la acción AJAX 'search' en todas las versiones hasta la 3.0.2, inclusive. Esto se debe a la fal…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2908
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Review Map by RevuKangaroo para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.7, inclusive, debido a un…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2909
|
8.8 |
HIGH
Network
|
-
|
-
|
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2910
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Expire Users para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta la 1.2.2, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el meta 'o…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|