Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.28%—Wpeventmanager WP User Profile AvatarAI20/6/202517/6/2026
Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.
AplazadaAlta (8.1)0.81%—Wedevs WP User FrontendAI5/6/202517/6/2026
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AplazadaAlta (8.8)0.92%—WP User Frontend PROAI5/6/202517/6/2026
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on…
AplazadaAlta (8.8)0.39%—John James Jacoby WP User ProfilesAI10/4/202517/6/2026
Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2.
AplazadaMedia (4.3)0.17%—WP User Profile AvatarAI16/1/202517/6/2026
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which…
AplazadaMedia (4.3)0.31%—Wedevs WP User FrontendAI2/1/202517/6/2026
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
AplazadaMedia (5.4)0.44%—Damir Calusic WP Users MediaAI9/12/202417/6/2026
Missing Authorization vulnerability in Damir Calusic WP users media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP users media: from n/a through 4.2.3.
AnalizadaMedia (4.3)0.38%—Wpusermanager WP User Manager23/11/202417/6/2026
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaMedia (4.3)0.44%—Wpusermanager WP User Manager23/11/202417/6/2026
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.48%—Lagunaisw WP Users Masquerade10/10/202417/6/2026
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for authenticated attackers, with subscriber-level permissions and…
AnalizadaAlta (7.2)0.44%—Wedevs WP User Frontend29/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
ModificadaMedia (4.3)0.18%—Wpusermanager WP User Manager26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10.
AplazadaAlta (8)0.37%—Iqbalrony WP User SwitchAI12/7/202417/6/2026
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0.
AplazadaAlta (7.2)0.64%—Wedevs WP User FrontendAI17/5/202417/6/2026
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
ModificadaMedia (6.1)0.51%—Lesterchan Wp-useronline27/11/202317/6/2026
The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.
ModificadaMedia (5.3)0.46%—Palmspark WP User Control13/9/202317/6/2026
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the…
ModificadaAlta (8.8)1.4%—WP User Switch Project WP User Switch6/6/202317/6/2026
The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.9)0.88%—Simple-membership-plugin Simple Membership WP User Import12/1/202317/6/2026
The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional…
ModificadaCrítica (9.8)4.8%—WP User Project WP User2/1/202317/6/2026
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
ModificadaMedia (4.8)0.56%—Wpseeds WP User15/12/202217/6/2026
The WP User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaAlta (8.8)1.1%—WP User Merger Project WP User Merger28/11/202217/6/2026
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
ModificadaAlta (8.8)1.1%—WP User Merger Project WP User Merger28/11/202217/6/2026
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
ModificadaAlta (8.8)1.1%—WP User Merger Project WP User Merger28/11/202217/6/2026
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
ModificadaCrítica (9.8)0.69%—Wedevs WP User Frontend21/11/202217/6/2026
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary…
ModificadaAlta (8.8)1.5%—Wp-users-exporter Project Wp-users-exporter6/9/202217/6/2026
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the…