Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.44%—Enrico Cantori 3D Avatar User ProfileAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D Avatar User Profile 3d-avatar-user-profile allows Reflected XSS.This issue affects 3D Avatar User Profile: from n/a through <= 1.0.0.
AplazadaMedia (4.3)0.43%—Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI9/12/202417/6/2026
Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0.
ModificadaMedia (4.3)0.41%—Cozmoslabs User Profile Picture21/6/202417/6/2026
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access…
AnalizadaMedia (5.4)0.42%—Wpeventsmanager User Profile Avatar15/4/202417/6/2026
The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaMedia (6.3)0.38%—Pickplugins User ProfileAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins User profile allows Stored XSS.This issue affects User profile: from n/a through 2.0.20.
ModificadaAlta (8.8)1.1%—Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields5/2/202417/6/2026
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible…
ModificadaMedia (4.3)0.47%—Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields5/2/202417/6/2026
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated…
ModificadaMedia (5.4)0.41%—Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields5/2/202417/6/2026
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This…
ModificadaMedia (4.3)0.40%—Wp-eventmanager User Profile Avatar22/1/202417/6/2026
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (5.4)0.55%—Paidmembershipspro Custom User Profile Fields FOR User Registration30/1/202317/6/2026
The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against…
ModificadaMedia (6.5)2.3%—User-meta User Meta User Profile Builder AND User Management8/6/202217/6/2026
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads
ModificadaMedia (4.8)0.59%—User-meta User Meta User Profile Builder AND User Management30/5/202217/6/2026
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (4.8)0.60%—Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor16/5/202217/6/2026
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)1.0%—Profilepress User Registration, Login Form, User Profile & Membership13/12/202117/6/2026
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.78%—Cozmoslabs User Profile Picture2/8/202117/6/2026
The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).
ModificadaAlta (7.5)4.8%💥 ExploitCozmoslabs User Profile Picture5/4/202117/6/2026
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
ModificadaAlta (7.5)2.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.1%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
ModificadaMedia (4.3)1.6%—Ultimatemember User Profile & Membership14/5/201817/6/2026
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.8)0.62%—Ultimatemember User Profile & Membership23/4/201817/6/2026
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.
ModificadaAlta (8.8)0.67%—Ultimatemember User Profile & Membership23/4/201817/6/2026
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
Orbitaley — Vulnerabilidades