Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.37%—Smackcoders WP Ultimate ExporterAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
AplazadaAlta (8.8)0.30%💥 PoCUltimatemember Ultimate MemberAI3/10/20266/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
AplazadaMedia (5.4)0.27%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated…
AplazadaMedia (6.5)0.28%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated…
AplazadaBaja (3.7)0.18%—Smackcoders WP Ultimate CSV ImporterAI3/10/20266/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a…
AplazadaBaja (3.5)0.14%—Smackcoders WP Ultimate CSV ImporterAI3/10/20266/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite…
AplazadaMedia (6.4)0.24%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
AplazadaAlta (7.5)0.34%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review…
AplazadaAlta (7.5)0.34%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is…
AplazadaAlta (7.5)0.25%—Wpmet WP Ultimate ReviewAI3/10/20266/10/2026
The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying…
AplazadaAlta (7.2)0.25%—Ultimatemember Ultimate MemberAI3/10/20266/10/2026
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This…
AplazadaAlta (7.5)0.40%—Ultimatemember Ultimate MemberAI3/10/20266/10/2026
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action.…
AplazadaAlta (7.6)0.28%💥 PoCUltimatemember Ultimate MemberAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
AplazadaMedia (5.3)0.20%—Smackcoders WP Ultimate CSV ImporterAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
AplazadaCrítica (9.8)0.58%—Ultimate MultisiteAI1/10/20261/10/2026
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible…
AplazadaMedia (6.5)0.16%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaAlta (7.2)0.40%—Themefic Ultimate Addons FOR Contact Form 7AI30/9/202630/9/2026
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
AplazadaAlta (7.1)0.18%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaMedia (6.5)0.16%—Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
AplazadaMedia (6.5)0.17%—Etoilewebdesign Ultimate FAQAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
AplazadaAlta (8.1)0.36%—Wpmet WP Ultimate ReviewAI22/9/202622/9/2026
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated…
AplazadaAlta (8.8)0.51%—Ultimatemember Ultimate MemberAI19/9/202621/9/2026
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that…
AplazadaAlta (7.5)0.26%—Wpswings Ultimate Gift Cards FOR WoocommerceAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption…
AplazadaAlta (7.5)0.21%—Ultimate Gift CardsAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
AplazadaMedia (6.5)0.30%—Ultimate Gift CardsAI9/9/20269/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In…
Orbitaley — Vulnerabilidades