Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.67% | — | Advancedplugins Ultimateimagetool | 20/7/2023 | 17/6/2026 | In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack. | |
| Modificada | Alta (8.8) | 0.27% | — | Ultimatemember Ultimate Member | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | Ultimatemember Ultimate Member | 4/7/2023 | 17/6/2026 | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild. | |
| Modificada | Media (4.3) | 0.48% | — | Wpswings Ultimate Gift Cards FOR Woocommerce | 1/7/2023 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card… | |
| Modificada | Media (4.8) | 0.50% | — | Etoilewebdesign Ultimate Product Catalog | 27/6/2023 | 17/6/2026 | The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.48% | — | Ultimatelysocial USM Premium | 27/6/2023 | 17/6/2026 | The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Media (4.8) | 0.37% | — | Wpmet WP Ultimate Review | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | |
| Modificada | Crítica (9.8) | 0.65% | — | Themefic Ultimate Addons FOR Contact Form 7 | 19/6/2023 | 17/6/2026 | Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions. | |
| Modificada | Media (4.8) | 0.47% | — | Ultimate Dashboard Project Ultimate Dashboard | 19/6/2023 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.82% | — | Themefic Ultimate Addons FOR Contact Form 7 | 9/6/2023 | 17/6/2026 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 3.1.23. This makes it possible for authenticated attackers of any authorization level to append additional SQL queries into already existing queries that can be used to… | |
| Modificada | Media (6.1) | 0.66% | — | Createit Ultimate Gdpr & Ccpa Compliance Toolkit | 7/6/2023 | 17/6/2026 | The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export_settings & import_settings functions in versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to change plugin settings and conduct attacks such as redirecting… | |
| Modificada | Crítica (9.8) | 1.6% | — | Etoilewebdesign Ultimate Reviews | 7/6/2023 | 17/6/2026 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Elementor | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.36% | — | Essentialplugin Hero Banner Ultimate | 4/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions. | |
| Modificada | Media (5.3) | 0.64% | — | Infopop Ultimate Bulletin Board | 27/4/2023 | 17/6/2026 | Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature. | |
| Modificada | Media (5.4) | 0.36% | — | Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Ultimate Noindex Nofollow Tool II Project Ultimate Noindex Nofollow Tool II | 16/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kilian Evang Ultimate Noindex Nofollow Tool II plugin <= 1.3 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Getshortcodes Shortcodes Ultimate | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions. | |
| Modificada | Media (6.5) | 0.65% | — | Getshortcodes Shortcodes Ultimate | 20/3/2023 | 17/6/2026 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default. | |
| Modificada | Media (6.5) | 0.65% | — | Getshortcodes Shortcodes Ultimate | 20/3/2023 | 17/6/2026 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password… | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Ultimatemember Jobboardwp | 19/12/2022 | 17/6/2026 | El complemento JobBoardWP de WordPress anterior a 1.2.2 no valida correctamente los nombres y tipos de archivos en sus funcionalidades de carga de archivos, lo que permite a usuarios no autenticados cargar archivos arbitrarios como PHP. | |
| Modificada | Media (5.4) | 0.55% | — | Oxilab Image Hover Effects Ultimate | 13/12/2022 | 17/6/2026 | Image Hover Effects Ultimate complemento para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de varios valores que se pueden agregar a Image Hover en las versiones 9.8.1 a 9.8.4 debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que atacantes autenticados… | |
| Modificada | Alta (7.2) | 3.0% | — | Ultimatemember Ultimate Member | 29/11/2022 | 17/6/2026 | El complemento Ultimate Member para WordPress es vulnerable a la ejecución remota de código en versiones hasta la 2.5.0 incluida a través de la función populate_dropdown_options que acepta la entrada proporcionada por el usuario y la pasa a través de call_user_func(). Esto está restringido a funciones PHP sin… | |
| Modificada | Alta (7.2) | 3.0% | — | Ultimatemember Ultimate Member | 29/11/2022 | 17/6/2026 | El complemento Ultimate Member para WordPress es vulnerable a la ejecución remota de código en versiones hasta la 2.5.0 incluida a través de la función get_option_value_from_callback que acepta la entrada proporcionada por el usuario y la pasa a través de call_user_func(). Esto hace posible que atacantes autenticados,… |