Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.44% | — | Wedevs DokanAI | 1/7/2026 | 1/7/2026 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `update_capabilities()` REST handler accepting arbitrary capability strings from the request body and passing them directly to… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Media (6.4) | 0.38% | — | Wedevs DokanAI | 27/6/2026 | 29/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs WemailAI | 26/6/2026 | 18/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2. | |
| Aplazada | Media (4.3) | 0.24% | — | Wedevs DokanAI | 18/6/2026 | 18/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info,… | |
| Aplazada | Alta (7.1) | 0.28% | — | Wedevs WemailAI | 17/6/2026 | 17/6/2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver… | |
| Aplazada | Media (4.3) | 0.11% | — | Wedevs Woocommerce Conversion TrackingAI | 11/6/2026 | 29/9/2026 | Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10. | |
| Aplazada | Alta (8.8) | 1.3% | — | Wedevs User FrontendAI | 8/5/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form… | |
| Aplazada | Media (5.3) | 0.33% | — | Wedevs Happy Addons FOR ElementorAI | 7/5/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8. | |
| Aplazada | Media (5.3) | 0.44% | — | Wedevs DokanAI | 2/5/2026 | 17/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |
| Aplazada | Media (5.3) | 0.26% | — | Wedevs WedocsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18. | |
| Aplazada | Alta (7.5) | 0.38% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wedevs WP ERPAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10. | |
| Aplazada | Alta (8.8) | 0.55% | — | Wedevs User FrontendAI | 26/2/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext'… | |
| Aplazada | Media (6.5) | 0.27% | — | Wedevs WemailAI | 21/2/2026 | 17/6/2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()` callback only validating the `X-WP-Nonce` header without… | |
| Aplazada | Media (6.5) | 0.18% | — | Wedevs Subscribe2AI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe2: from n/a through <= 10.44. | |
| Aplazada | Alta (8.1) | 0.30% | — | Wedevs DokanAI | 20/1/2026 | 17/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled… | |
| Aplazada | Media (5.3) | 0.31% | — | Wedevs WemailAI | 20/1/2026 | 17/6/2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST API trusting the `x-wemail-user` HTTP header to identify users without… | |
| Aplazada | Media (5.3) | 0.90% | 💥 Exploit | Wedevs WP User FrontendAI | 2/1/2026 | 17/6/2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,… | |
| Aplazada | Media (6.5) | 0.26% | — | Wedevs WP Project ManagerAI | 29/12/2025 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Wedevs WP ERPAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: from n/a through <= 1.16.6. | |
| Aplazada | Media (5.3) | 0.24% | — | Wedevs DokanAI | 16/12/2025 | 17/6/2026 | The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/dokan/v1/wholesale/register` REST API endpoint in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to enumerate users and retrieve their email… | |
| Aplazada | Media (5.3) | 0.30% | — | Wedevs WP ERPAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.16.7. |