Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4. | |
| Aplazada | Media (6.1) | 0.22% | — | Ultimatemember Ultimate MemberAI | 18/2/2026 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input… | |
| Aplazada | Media (5.3) | 0.25% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.5.34. | |
| Aplazada | Alta (8.6) | 0.36% | — | Mult-e-cart UltimateAI | 1/2/2026 | 17/6/2026 | Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system. | |
| Aplazada | Media (5.1) | 0.34% | — | Ultimate POSAI | 1/2/2026 | 17/6/2026 | Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ultimate Project Manager CRM PROAI | 29/1/2026 | 17/6/2026 | The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively… | |
| Aplazada | Media (5.3) | 0.24% | — | Rustaurius Ultimate ReviewsAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16. | |
| Aplazada | Alta (7.5) | 0.33% | — | Wpxpo Postx Ultimate-postAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 5.0.3. | |
| Aplazada | Media (5.9) | 0.29% | — | Benjamin Intal Stackable Ultimate Gutenberg BlocksAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Stored XSS.This issue affects Stackable: from n/a through <= 3.19.5. | |
| Aplazada | Media (5.4) | 0.20% | — | Buddhathemes Wedesigntech Ultimate Booking AddonAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.19% | — | Bdthemes Ultimate Store KITAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.9.4. | |
| Aplazada | Media (6.4) | 0.22% | — | Ultimatemember ForumwpAI | 6/1/2026 | 17/6/2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's Display Name in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.4) | 0.27% | — | WP Import Ultimate CSV XML ImporterAI | 1/1/2026 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial… | |
| Aplazada | Media (5.3) | 0.28% | — | Ultimate Post KITAI | 31/12/2025 | 17/6/2026 | The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered… | |
| Aplazada | Media (5.3) | 0.23% | — | Wpxpo Postx Ultimate-postAI | 24/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3. | |
| Analizada | Alta (7.7) | 0.15% | — | K7computing K7 Ultimate Security | 22/12/2025 | 17/6/2026 | An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key,… | |
| Aplazada | Media (6.4) | 0.24% | — | Ultimatemember Ultimate MemberAI | 21/12/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insufficient input sanitization and output… | |
| Aplazada | Media (5.3) | 0.52% | — | Ultimatemember Ultimate MemberAI | 20/12/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy… | |
| Aplazada | Alta (7.5) | 0.28% | — | Userelements Ultimate Member Widgets FOR ElementorAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ultimate-member-widgets-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Member Widgets for Elementor: from n/a through <= 2.3. | |
| Aplazada | Alta (7.2) | 0.40% | — | Wpxpo Postx Ultimate-postAI | 18/12/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpxpo Postx Ultimate PostAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 4.1.36. | |
| Aplazada | Media (4.3) | 0.32% | — | Ultimatemember Ultimate MemberAI | 17/12/2025 | 17/6/2026 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is applied during rendering. This makes it… | |
| Aplazada | Media (6.4) | 0.29% | — | Ultimatemember Ultimate MemberAI | 17/12/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output… | |
| Aplazada | Media (5.4) | 0.20% | — | Nitesh Ultimate AuctionAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Auction : from n/a through <= 4.3.3. | |
| Aplazada | Media (5.3) | 0.29% | — | Nitesh Ultimate-auctionAI | 16/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Nitesh Ultimate Auction ultimate-auction allows Retrieve Embedded Sensitive Data.This issue affects Ultimate Auction : from n/a through <= 4.3.3. |