Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15382

Publication date:
30/07/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-16524

Publication date:
30/07/2026
A command injection flaw in PCP&amp;#39;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.<br /> This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14923

Publication date:
30/07/2026
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15240

Publication date:
30/07/2026
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15250

Publication date:
30/07/2026
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site&amp;#39;s booking approval workflow.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15252

Publication date:
30/07/2026
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site&amp;#39;s Google Indexing API integration, submitting or removing the site&amp;#39;s URLs from Google&amp;#39;s index and consuming its indexing quota.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15054

Publication date:
30/07/2026
The Bit Form WordPress plugin before 3.1.2 does not enforce a form&amp;#39;s active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15153

Publication date:
30/07/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2&amp;#39;s booking-management roles to perform SQL injection attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15235

Publication date:
30/07/2026
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking&amp;#39;s full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14305

Publication date:
30/07/2026
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14310

Publication date:
30/07/2026
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&amp;A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&amp;A threads of other courses and to inject replies into them.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14592

Publication date:
30/07/2026
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026