Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.12% | — | Ayecode UserswpAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48. | |
| Aplazada | Media (5.3) | 0.22% | — | Vanquish User Extra FieldsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Extra Fields: from n/a through <= 16.8. | |
| Aplazada | Alta (7.1) | 0.12% | — | Wpexperts NEW User ApproveAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Request Forgery.This issue affects New User Approve: from n/a through <= 3.2.3. | |
| Aplazada | Media (5.3) | 0.29% | — | Joelhardi User Spam RemoverAI | 9/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Joel User Spam Remover user-spam-remover allows Retrieve Embedded Sensitive Data.This issue affects User Spam Remover: from n/a through <= 1.1. | |
| Aplazada | Alta (8.8) | 0.18% | — | User Generator AND ImporterAI | 5/12/2025 | 25/9/2026 | The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to elevate user privileges by creating arbitrary… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Pickplugins User VerificationAI | 5/12/2025 | 17/6/2026 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that an OTP was generated before comparing it… | |
| Aplazada | Media (6.5) | 0.16% | — | Export ALL Posts Products Orders Refunds UsersAI | 2/12/2025 | 17/6/2026 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensitive… | |
| Aplazada | Media (5.3) | 0.28% | — | Hide Category BY User RoleAI | 27/11/2025 | 17/6/2026 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the… | |
| Aplazada | Media (5.3) | 0.25% | — | Ayecode UserswpAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47. | |
| Aplazada | Alta (7.2) | 0.23% | — | Simple User RegistrationAI | 21/11/2025 | 30/9/2026 | The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to, and including, 6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpexperts NEW User ApproveAI | 19/11/2025 | 17/6/2026 | The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API key validation using loose equality comparison. This makes it possible for unauthenticated attackers to retrieve personally identifiable information (PII),… | |
| Aplazada | Media (6.6) | 0.27% | — | Simple User Import ExportAI | 18/11/2025 | 17/6/2026 | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which… | |
| Aplazada | Alta (7.2) | 0.36% | — | Multiple Roles PER UserAI | 18/11/2025 | 17/6/2026 | The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mrpu_add_multiple_roles_ui' and 'mrpu_save_multiple_user_roles' functions in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, granted… | |
| Analizada | Media (6.1) | 0.26% | — | Remyandrade Modern User Account Generator | 7/11/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to improper sanitization of user-supplied input… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Wpusermanager WP User ManagerAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12. | |
| Aplazada | Crítica (10) | 0.46% | — | Addify Custom User Registration Fields FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Custom User Registration Fields for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Alta (7.5) | 0.46% | — | Premmerce User RolesAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows PHP Local File Inclusion.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bnovotny User-registration-aideAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bnovotny User Registration Aide user-registration-aide allows Reflected XSS.This issue affects User Registration Aide: from n/a through <= 1.5.3.8. | |
| Aplazada | Alta (7.1) | 0.13% | — | Andriassundskard WpnamedusersAI | 6/11/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This issue affects wpNamedUsers: from n/a through <= 0.5. | |
| Aplazada | Media (6.3) | 0.19% | — | ACE User ManagementAI | 5/11/2025 | 17/6/2026 | The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Simple User CapabilitiesAI | 4/11/2025 | 17/6/2026 | The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to elevate the role of any user account to administrator. | |
| Aplazada | Media (5.3) | 0.29% | — | Simple User CapabilitiesAI | 4/11/2025 | 17/6/2026 | The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to reset any user's capabilities. | |
| Analizada | Media (4.6) | 0.21% | — | Nababur Simple-user-management-system | 3/11/2025 | 17/6/2026 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser | |
| Aplazada | Alta (8.8) | 0.70% | — | Wordpress User Extra FieldsAI | 31/10/2025 | 7/10/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… |