Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2963▼ 120 respecto a la semana anterior
Críticas / altas1404▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.18%—User Generator AND ImporterAI5/12/202525/9/2026
The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to elevate user privileges by creating arbitrary…
AplazadaAlta (8.8)0.55%—Kraftplugins Demo Importer PlusAI5/12/202525/9/2026
The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible…
AplazadaAlta (8.8)0.69%—URL Image ImporterAI21/11/202517/6/2026
The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in the 'uimptr_import_image_from_url()'…
AplazadaMedia (4.3)0.26%—WP Import Ultimate CSV XML ImporterAI12/11/202517/6/2026
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level…
AplazadaMedia (5.4)0.28%—Themeshopy TS Demo ImporterAI27/10/202517/6/2026
Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through <= 0.1.3.
AplazadaMedia (4.3)0.13%—Theme ImporterAI15/10/202517/6/2026
The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation when processing form submissions in the theme-importer.php file. This makes it possible for unauthenticated attackers to trigger arbitrary file…
AplazadaAlta (8.6)0.33%—CTL Behance Importer LiteAI2/10/202517/6/2026
The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AplazadaMedia (4.3)0.14%—DI Themes Demo Site ImporterAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer allows Cross Site Request Forgery.This issue affects Di Themes Demo Site Importer: from n/a through <= 1.2.
AplazadaAlta (8.8)0.73%—WP Import Ultimate CSV XML ImporterAI17/9/202525/9/2026
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.24%—Blaze Demo ImporterAI16/9/202517/6/2026
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (8.1)0.70%—Catalog Importer Scraper CrawlerAI11/9/202517/6/2026
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This…
AplazadaMedia (4.3)0.13%—Ultimate TAG Warrior ImporterAI29/8/202517/6/2026
The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site…
AplazadaMedia (5.9)0.26%—Jason Judge CSV Importer ImprovedAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Judge CSV Importer Improved csv-importer-improved allows Stored XSS.This issue affects CSV Importer Improved: from n/a through <= 0.6.1.
AnalizadaAlta (8.8)0.59%—Axlethemes Axle Demo Importer10/6/202517/6/2026
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
AplazadaAlta (7.1)0.22%—Pressaholic Wordpress Video Robot - THE Ultimate Video ImporterAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress Video Robot - The Ultimate Video Importer.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.
AnalizadaAlta (7.2)0.56%💥 PoCAleapp CSV Mass Importer17/5/202517/6/2026
The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
AnalizadaMedia (6.1)0.33%—Cr1000 Affiliateimportereb15/5/202517/6/2026
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6.1)0.57%💥 ExploitCr1000 Affiliateimportereb15/5/202517/6/2026
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.2)0.57%—Michael Cannon Flickr Shortcode ImporterAI24/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This issue affects Flickr Shortcode Importer: from n/a through <= 2.2.3.
AplazadaCrítica (9.6)0.26%—Uncodethemes Ultra Demo ImporterAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5.
AplazadaAlta (7.2)0.78%—Wordpress ImporterAI26/3/202517/6/2026
The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP…
AplazadaAlta (7.1)0.39%—Dsgnwrks Twitter ImporterAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Sternberg DsgnWrks Twitter Importer dsgnwrks-twitter-importer allows Reflected XSS.This issue affects DsgnWrks Twitter Importer: from n/a through <= 1.1.4.
AnalizadaAlta (7.2)0.68%—Misterpah Mambo Joomla Importer22/2/202517/6/2026
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a…
AplazadaAlta (7.1)0.33%—Idiatech Catalog Importer Scraper CrawlerAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idiatech Catalog Importer, Scraper & Crawler intelligent-importer allows Reflected XSS.This issue affects Catalog Importer, Scraper & Crawler: from n/a through <= 5.1.3.
AplazadaMedia (6.4)0.31%—Etsy ImporterAI25/1/202517/6/2026
The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
Orbitaley — Vulnerabilidades