Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2963▼ 120 respecto a la semana anterior
Críticas / altas1404▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.18% | — | User Generator AND ImporterAI | 5/12/2025 | 25/9/2026 | The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to elevate user privileges by creating arbitrary… | |
| Aplazada | Alta (8.8) | 0.55% | — | Kraftplugins Demo Importer PlusAI | 5/12/2025 | 25/9/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Aplazada | Alta (8.8) | 0.69% | — | URL Image ImporterAI | 21/11/2025 | 17/6/2026 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in the 'uimptr_import_image_from_url()'… | |
| Aplazada | Media (4.3) | 0.26% | — | WP Import Ultimate CSV XML ImporterAI | 12/11/2025 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Media (5.4) | 0.28% | — | Themeshopy TS Demo ImporterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through <= 0.1.3. | |
| Aplazada | Media (4.3) | 0.13% | — | Theme ImporterAI | 15/10/2025 | 17/6/2026 | The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation when processing form submissions in the theme-importer.php file. This makes it possible for unauthenticated attackers to trigger arbitrary file… | |
| Aplazada | Alta (8.6) | 0.33% | — | CTL Behance Importer LiteAI | 2/10/2025 | 17/6/2026 | The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Aplazada | Media (4.3) | 0.14% | — | DI Themes Demo Site ImporterAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer allows Cross Site Request Forgery.This issue affects Di Themes Demo Site Importer: from n/a through <= 1.2. | |
| Aplazada | Alta (8.8) | 0.73% | — | WP Import Ultimate CSV XML ImporterAI | 17/9/2025 | 25/9/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.24% | — | Blaze Demo ImporterAI | 16/9/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.1) | 0.70% | — | Catalog Importer Scraper CrawlerAI | 11/9/2025 | 17/6/2026 | The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This… | |
| Aplazada | Media (4.3) | 0.13% | — | Ultimate TAG Warrior ImporterAI | 29/8/2025 | 17/6/2026 | The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site… | |
| Aplazada | Media (5.9) | 0.26% | — | Jason Judge CSV Importer ImprovedAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Judge CSV Importer Improved csv-importer-improved allows Stored XSS.This issue affects CSV Importer Improved: from n/a through <= 0.6.1. | |
| Analizada | Alta (8.8) | 0.59% | — | Axlethemes Axle Demo Importer | 10/6/2025 | 17/6/2026 | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server | |
| Aplazada | Alta (7.1) | 0.22% | — | Pressaholic Wordpress Video Robot - THE Ultimate Video ImporterAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress Video Robot - The Ultimate Video Importer.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0. | |
| Analizada | Alta (7.2) | 0.56% | 💥 PoC | Aleapp CSV Mass Importer | 17/5/2025 | 17/6/2026 | The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.33% | — | Cr1000 Affiliateimportereb | 15/5/2025 | 17/6/2026 | The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6.1) | 0.57% | 💥 Exploit | Cr1000 Affiliateimportereb | 15/5/2025 | 17/6/2026 | The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.2) | 0.57% | — | Michael Cannon Flickr Shortcode ImporterAI | 24/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This issue affects Flickr Shortcode Importer: from n/a through <= 2.2.3. | |
| Aplazada | Crítica (9.6) | 0.26% | — | Uncodethemes Ultra Demo ImporterAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5. | |
| Aplazada | Alta (7.2) | 0.78% | — | Wordpress ImporterAI | 26/3/2025 | 17/6/2026 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP… | |
| Aplazada | Alta (7.1) | 0.39% | — | Dsgnwrks Twitter ImporterAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Sternberg DsgnWrks Twitter Importer dsgnwrks-twitter-importer allows Reflected XSS.This issue affects DsgnWrks Twitter Importer: from n/a through <= 1.1.4. | |
| Analizada | Alta (7.2) | 0.68% | — | Misterpah Mambo Joomla Importer | 22/2/2025 | 17/6/2026 | The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a… | |
| Aplazada | Alta (7.1) | 0.33% | — | Idiatech Catalog Importer Scraper CrawlerAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idiatech Catalog Importer, Scraper & Crawler intelligent-importer allows Reflected XSS.This issue affects Catalog Importer, Scraper & Crawler: from n/a through <= 5.1.3. | |
| Aplazada | Media (6.4) | 0.31% | — | Etsy ImporterAI | 25/1/2025 | 17/6/2026 | The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |