Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%💥 PoCIptanus Wordpress File Upload8/1/202517/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
ModificadaCrítica (9.8)4.5%💥 PoCIptanus Wordpress File Upload8/1/202517/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined…
AnalizadaMedia (4.3)0.35%—Iptanus Wordpress File Upload7/1/202517/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AnalizadaBaja (3.5)0.25%—Iptanus Wordpress File Upload1/11/202417/6/2026
Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7.
AplazadaMedia (6.4)0.38%—Wpforms File Upload TypesAI25/10/202417/6/2026
The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…
AnalizadaCrítica (9.8)93%💥 ExploitIptanus Wordpress File Upload12/10/202417/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the…
AnalizadaMedia (6.1)0.43%—Ninjaforms Ninja Forms File Uploads7/9/202417/6/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaMedia (4.3)0.56%—Infiniteuploads BIG File Uploads7/9/202417/6/2026
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing a file path in an error message. This makes it possible for authenticated attackers, with author-level access and above,…
AnalizadaMedia (6.1)0.46%—Iptanus Wordpress File Upload16/8/202417/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (6.1)0.36%—Iptanus Wordpress File Upload7/8/202417/6/2026
The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.
AnalizadaMedia (6.1)15%💥 ExploitIptanus Wordpress File Upload6/8/202417/6/2026
The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (4.3)0.69%—Iptanus Wordpress File Upload16/7/202417/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to…
AplazadaMedia (4.3)0.17%—Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI1/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11.
ModificadaAlta (7.5)0.71%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 72/5/202417/6/2026
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive…
ModificadaMedia (5.4)0.36%—Iptanus Wordpress File Upload9/4/202417/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaBaja (3.5)0.49%—Wp-file-uploadAI1/4/202417/6/2026
A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to…
AplazadaCrítica (10)0.81%—Mainwp File Uploader ExtensionAI26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.
ModificadaCrítica (9.8)0.60%—Codedropz Drag AND Drop Multiple File Upload FOR Woocommerce21/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.
ModificadaAlta (8.8)0.26%—Infiniteuploads BIG File Uploads22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Infinite Uploads Big File Uploads – Increase Maximum File Upload Size plugin <= 2.1.1 versions.
ModificadaCrítica (9.8)1.8%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 722/11/202317/6/2026
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files…
ModificadaMedia (5.4)0.39%—Ashik Cits Support Svg, Webp Media AND Ttf,otf File Upload31/10/202317/6/2026
The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaMedia (5.4)0.45%—Codedropz Drag AND Drop Multiple File Uploader16/10/202317/6/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
ModificadaMedia (5.4)0.39%—Iptanus Wordpress File Upload16/10/202317/6/2026
The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.38%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.9)1.7%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)…
Orbitaley — Vulnerabilidades