Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.32% | — | Cmorillas1 Shortcodes Blocks Creator Ultimate | 7/12/2024 | 17/6/2026 | The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (5.3) | 0.37% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to change the template used… | |
| Modificada | Media (4.3) | 0.34% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Modificada | Media (6.1) | 0.35% | — | Ultimatemember Forumwp | 6/12/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.40% | — | Ultimatemember Forumwp | 6/12/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpswings Woocommerce Ultimate Gift CardAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Reflected XSS.This issue affects WooCommerce Ultimate Gift Card: from n/a through < 2.9.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Webcodingplace Ultimate Classified ListingsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through <= 1.7. | |
| Analizada | Media (6.1) | 0.47% | — | Ultimatemember Jobboardwp | 23/11/2024 | 17/6/2026 | The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.47% | — | Ultimate Youtube Video Shorts Player With VimeoAI | 22/11/2024 | 17/6/2026 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (4.3) | 0.56% | — | Codelizar Ultimate Youtube Video & Shorts Player With Vimeo | 21/11/2024 | 17/6/2026 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Media (4.3) | 0.58% | — | Ultimatemember Ultimate Member | 21/11/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, and… | |
| Aplazada | Alta (7.5) | 0.57% | — | Webcodingplace Ultimate Classified ListingsAI | 20/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP Local File Inclusion.This issue affects Ultimate Classified Listings: from n/a through <= 1.7. | |
| Aplazada | Media (6.5) | 0.32% | — | Dragwyb Ultimate Flipbox Addon FOR ElementorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dragwyb Ultimate Flipbox Addon for Elementor ultimate-flipbox-addon-for-elementor allows Stored XSS.This issue affects Ultimate Flipbox Addon for Elementor: from n/a through 1.0.4. | |
| Aplazada | Media (6.5) | 0.37% | — | Ultimate AccordionAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Shiddikur Rahman Ultimate Accordion ultimate-accordion allows DOM-Based XSS.This issue affects Ultimate Accordion: from n/a through <= 1.0. | |
| Aplazada | Media (5.9) | 0.39% | — | Wpxpo Postx Ultimate-postAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultimate-post allows Stored XSS.This issue affects PostX: from n/a through <= 4.1.15. | |
| Analizada | Media (4.3) | 0.41% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 5/11/2024 | 17/6/2026 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive… | |
| Aplazada | Media (6.4) | 0.35% | — | Cmorillas1 Shortcodes Blocks Creator UltimateAI | 5/11/2024 | 17/6/2026 | The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' shortcode in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Media (5.4) | 0.26% | — | Joshlobe Ultimate Tinymce | 30/10/2024 | 17/6/2026 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (5.4) | 0.40% | — | Getshortcodes Shortcodes Ultimate | 23/10/2024 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.27% | — | Pepro DEV Group Pepro Ultimate InvoiceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice pepro-ultimate-invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through <= 2.0.6. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Wpindeed Ultimate Membership PROAI | 16/10/2024 | 17/6/2026 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
| Aplazada | Crítica (9.8) | 0.57% | — | UltimateaiAI | 16/10/2024 | 17/6/2026 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the 'ultimate_ai_register_or_login_with_google' function. This makes it possible for unauthenticated attackers to log in as any… | |
| Aplazada | Media (5.6) | 0.34% | — | UltimateaiAI | 16/10/2024 | 17/6/2026 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty value check and a missing default activated value check in the 'ultimate_ai_change_pass' function. This makes it possible for unauthenticated attackers to reset the… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Ultimate Post GridAI | 11/10/2024 | 17/6/2026 | The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Bdthemes Ultimate Store KITAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.0.5. |