Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Smackcoders WP Ultimate ExporterAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0. | |
| Aplazada | Alta (8.8) | 0.30% | 💥 PoC | Ultimatemember Ultimate MemberAI | 3/10/2026 | 6/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1. | |
| Aplazada | Media (5.4) | 0.27% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.28% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Aplazada | Baja (3.7) | 0.18% | — | Smackcoders WP Ultimate CSV ImporterAI | 3/10/2026 | 6/10/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a… | |
| Aplazada | Baja (3.5) | 0.14% | — | Smackcoders WP Ultimate CSV ImporterAI | 3/10/2026 | 6/10/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled. | |
| Aplazada | Alta (7.5) | 0.34% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review… | |
| Aplazada | Alta (7.5) | 0.34% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is… | |
| Aplazada | Alta (7.5) | 0.25% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying… | |
| Aplazada | Alta (7.2) | 0.25% | — | Ultimatemember Ultimate MemberAI | 3/10/2026 | 6/10/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Alta (7.5) | 0.40% | — | Ultimatemember Ultimate MemberAI | 3/10/2026 | 6/10/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action.… | |
| Aplazada | Alta (7.6) | 0.28% | 💥 PoC | Ultimatemember Ultimate MemberAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1. | |
| Aplazada | Media (5.3) | 0.20% | — | Smackcoders WP Ultimate CSV ImporterAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Ultimate MultisiteAI | 1/10/2026 | 1/10/2026 | The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible… | |
| Aplazada | Media (6.5) | 0.16% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Etoilewebdesign Ultimate FAQAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | |
| Aplazada | Alta (8.1) | 0.36% | — | Wpmet WP Ultimate ReviewAI | 22/9/2026 | 22/9/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.51% | — | Ultimatemember Ultimate MemberAI | 19/9/2026 | 21/9/2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that… | |
| Aplazada | Alta (7.5) | 0.26% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption… | |
| Aplazada | Alta (7.5) | 0.21% | — | Ultimate Gift CardsAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid. | |
| Aplazada | Media (6.5) | 0.30% | — | Ultimate Gift CardsAI | 9/9/2026 | 9/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In… |