Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.59% | — | Dynamiapps Frontend AdminAI | 11/8/2026 | 12/8/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dynamiapps Frontend AdminAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Media (5.4) | 0.13% | — | Najeebmedia Frontend File ManagerAI | 2/8/2026 | 26/8/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,… | |
| Aplazada | Alta (8.8) | 0.45% | — | Dynamiapps Frontend AdminAI | 31/7/2026 | 26/8/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output… | |
| Aplazada | Media (6.5) | 0.30% | — | Dynamiapps Frontend AdminAI | 30/7/2026 | 30/7/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs User FrontendAI | 27/7/2026 | 27/7/2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads… | |
| Aplazada | Media (5.3) | 0.42% | — | Wedevs User FrontendAI | 9/7/2026 | 9/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes… | |
| Aplazada | Media (5.3) | 0.31% | — | User FrontendAI | 8/7/2026 | 8/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This… | |
| Aplazada | Alta (8.7) | 0.39% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 7/7/2026 | 7/7/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Alta (8.1) | 0.60% | — | Najeebmedia Frontend File ManagerAI | 28/6/2026 | 29/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase… | |
| Aplazada | Media (6.5) | 0.47% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 26/6/2026 | 26/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin… | |
| Aplazada | Alta (7.5) | 0.41% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers. | |
| Aplazada | Media (5.4) | 0.23% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with… | |
| Aplazada | Alta (8.5) | 0.35% | — | Effress Woocommerce Frontend Manager UltimateAI | 17/6/2026 | 17/6/2026 | Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. | |
| Aplazada | Media (4.3) | 0.26% | — | Weplugins User FrontendAI | 9/6/2026 | 23/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Media (4.3) | 0.19% | — | Frontend User NotesAI | 6/6/2026 | 23/7/2026 | The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in user into visiting… | |
| Aplazada | Media (4.9) | 0.29% | — | Dynamiapps Frontend AdminAI | 29/5/2026 | 21/7/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 1.2% | — | Dynamiapps Frontend AdminAI | 28/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When… | |
| Aplazada | Alta (8.8) | 0.75% | — | Dynamiapps Frontend AdminAI | 28/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.8) | 0.77% | — | Dynamiapps Frontend AdminAI | 15/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post… | |
| Aplazada | Alta (8.8) | 1.3% | — | Wedevs User FrontendAI | 8/5/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form… | |
| Aplazada | Media (6.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 3/5/2026 | 17/6/2026 | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Glowlogix WP Frontend ProfileAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9. |