Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.41%—Properfraction Profilepress3/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
ModificadaMedia (5.4)0.41%—Properfraction Profilepress3/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
ModificadaAlta (8.1)0.99%—Cozmoslabs Profile Builder27/4/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function…
ModificadaMedia (4.8)0.42%—Properfraction Profilepress6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.
ModificadaMedia (6.1)0.41%—Properfraction Profilepress29/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.
ModificadaAlta (8.8)0.82%—Metagauss Profilegrid20/3/202317/6/2026
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (6.5)0.77%—Cozmoslabs Profile Builder14/2/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This…
ModificadaMedia (5.4)0.55%—Paidmembershipspro Custom User Profile Fields FOR User Registration30/1/202317/6/2026
The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against…
ModificadaMedia (4.8)0.66%—Properfraction Profilepress23/12/202217/6/2026
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaMedia (4.8)0.71%—Properfraction Profilepress23/12/202217/6/2026
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaAlta (8.8)0.70%—Metagauss Profilegrid17/11/202217/6/2026
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
ModificadaMedia (6.1)1.0%💥 ExploitMetagauss Profilegrid14/11/202217/6/2026
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (7.3)0.17%—Intel Vtune Profiler11/11/202217/6/2026
Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)0.27%—Cozmoslabs Profile Builder11/10/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.
ModificadaAlta (7.8)0.27%—Intel Vtune Profiler18/8/202217/6/2026
Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)2.3%—User-meta User Meta User Profile Builder AND User Management8/6/202217/6/2026
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
ModificadaMedia (4.8)0.59%—User-meta User Meta User Profile Builder AND User Management30/5/202217/6/2026
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.8)0.60%—Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor16/5/202217/6/2026
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.65%—Cozmoslabs Profile Builder4/4/202217/6/2026
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)2.7%💥 ExploitCozmoslabs Profile Builder24/2/202217/6/2026
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes…
ModificadaMedia (5.4)0.60%—Fivestarplugins Five Star Business Profile AND Schema21/2/202217/6/2026
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of…
ModificadaMedia (5.4)0.90%—Metagauss Profilegrid18/1/202217/6/2026
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user…
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue