Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.69% | — | URL Image ImporterAI | 21/11/2025 | 17/6/2026 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in the 'uimptr_import_image_from_url()'… | |
| Aplazada | Alta (7.2) | 0.51% | — | WP ImportAI | 19/11/2025 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to deserialization of untrusted data supplied via CSV file imports in the import_single_post_as_csv function within SingleImportExport.php. This… | |
| Aplazada | Media (6.6) | 0.27% | — | Simple User Import ExportAI | 18/11/2025 | 17/6/2026 | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted input into exported CSV files, which… | |
| Aplazada | Media (4.3) | 0.20% | — | Webtoffee Order Export AND Order Import FOR WoocommerceAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7. | |
| Aplazada | Alta (8.8) | 0.64% | — | Wpallimport WP ALL ImportAI | 13/11/2025 | 17/6/2026 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.9.6. This is due to the use of eval() on unsanitized user-supplied input in the pmxi_if function within helpers/functions.php. This makes it possible… | |
| Aplazada | Media (4.3) | 0.26% | — | WP Import Ultimate CSV XML ImporterAI | 12/11/2025 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Alta (7.1) | 0.19% | — | Icopydoc Import From YMLAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Import from YML import-from-yml allows Reflected XSS.This issue affects Import from YML: from n/a through <= 3.1.17. | |
| Aplazada | Alta (7.5) | 0.46% | — | Thimpress Learnpress Export ImportAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows PHP Local File Inclusion.This issue affects LearnPress Export Import: from n/a through <= 4.1.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Codexthemes Thegem Demo ImportAI | 6/11/2025 | 5/10/2026 | Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBakery): from n/a through <= 5.10.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Sidngr Import Export FOR WoocommerceAI | 4/11/2025 | 17/6/2026 | The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Media (4.9) | 0.47% | 💥 PoC | Importwp Import WPAI | 1/11/2025 | 17/6/2026 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary absolute file paths without proper validation in the 'attach_file()' function when… | |
| Aplazada | Media (5.4) | 0.28% | — | Themeshopy TS Demo ImporterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through <= 0.1.3. | |
| Aplazada | Media (4.3) | 0.20% | — | LLM Hubspot Blog ImportAI | 24/10/2025 | 30/9/2026 | The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX endpoint in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Thimpress Learnpress Export ImportAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows Reflected XSS.This issue affects LearnPress Export Import: from n/a through <= 4.0.9. | |
| Aplazada | Media (4.3) | 0.13% | — | Theme ImporterAI | 15/10/2025 | 17/6/2026 | The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation when processing form submissions in the theme-importer.php file. This makes it possible for unauthenticated attackers to trigger arbitrary file… | |
| Aplazada | Alta (7.2) | 0.69% | — | Demo Import KITAI | 15/10/2025 | 17/6/2026 | The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.1.0 via the import functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the… | |
| Aplazada | Alta (8.6) | 0.33% | — | CTL Behance Importer LiteAI | 2/10/2025 | 17/6/2026 | The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Aplazada | Media (4.3) | 0.14% | — | DI Themes Demo Site ImporterAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer allows Cross Site Request Forgery.This issue affects Di Themes Demo Site Importer: from n/a through <= 1.2. | |
| Aplazada | Alta (8.1) | 0.63% | — | WP ImportAI | 17/9/2025 | 25/9/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 0.75% | — | WP Import Ultimate CSV XML ImporterAI | 17/9/2025 | 25/9/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.24% | — | Blaze Demo ImporterAI | 16/9/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.1) | 0.70% | — | Catalog Importer Scraper CrawlerAI | 11/9/2025 | 17/6/2026 | The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This… | |
| Aplazada | Alta (7.7) | 0.29% | — | WP ImportAI | 10/9/2025 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_details' AJAX action in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (7.2) | 0.56% | — | Import ANY XML CSV OR Excel File TO WordpressAI | 10/9/2025 | 17/6/2026 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (4.3) | 0.13% | — | Ultimate TAG Warrior ImporterAI | 29/8/2025 | 17/6/2026 | The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site… |