Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.38% | — | Extendons Woocommerce CSV Import ExportAI | 28/8/2025 | 25/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export extendons-eo-wooimport-export allows Path Traversal.This issue affects WooCommerce csv import export: from n/a through <= 2.0.6. | |
| Analizada | Alta (8.8) | 0.68% | — | Vjinfotech WP Import Export Lite | 5/8/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions… | |
| Analizada | Alta (8.8) | 0.71% | — | Vjinfotech WP Import Export Lite | 5/8/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions… | |
| Aplazada | Alta (7.1) | 0.14% | — | Atakanau Import CDN Remote ImagesAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows Stored XSS.This issue affects Import CDN-Remote Images: from n/a through <= 2.1.2. | |
| Analizada | Crítica (9.8) | 7.5% | 💥 Exploit | Ait-themes CSV Import / Export | 12/7/2025 | 17/6/2026 | The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for unauthorized attackers to upload arbitrary files… | |
| Aplazada | Media (4.3) | 0.15% | — | Ryanpcmcquen Import External AttachmentsAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ryanpcmcquen Import external attachments import-external-attachments allows Cross Site Request Forgery.This issue affects Import external attachments: from n/a through <= 1.5.12. | |
| Aplazada | Alta (7.5) | 0.29% | — | Enguerranws Import Youtube Videos AS WP PostAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in enguerranws Import YouTube videos as WP Posts import-youtube-videos-as-wp-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Import YouTube videos as WP Posts: from n/a through <= 2.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Jason Judge CSV Importer ImprovedAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Judge CSV Importer Improved csv-importer-improved allows Stored XSS.This issue affects CSV Importer Improved: from n/a through <= 0.6.1. | |
| Aplazada | Crítica (9.8) | 0.63% | 💥 PoC | Rest API Custom API Generator FOR Cross Platform AND Import Export IN WPAI | 13/6/2025 | 17/6/2026 | The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api… | |
| Analizada | Alta (8.8) | 0.59% | — | Axlethemes Axle Demo Importer | 10/6/2025 | 17/6/2026 | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server | |
| Aplazada | Media (6.4) | 0.29% | — | Wordpress Comments Import ExportAI | 2/6/2025 | 17/6/2026 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails to properly sanitize and escape FTP settings parameters. This makes… | |
| Modificada | Crítica (9.8) | 0.71% | — | Xylusthemes WP Smart Import | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes WP Smart Import wp-smart-import allows PHP Local File Inclusion.This issue affects WP Smart Import: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Pressaholic Wordpress Video Robot - THE Ultimate Video ImporterAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPress Video Robot - The Ultimate Video Importer.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0. | |
| Modificada | Media (5.4) | 0.26% | — | Xylusthemes Import Social Events | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events import-facebook-events allows Stored XSS.This issue affects Import Social Events: from n/a through <= 1.8.5. | |
| Analizada | Alta (7.2) | 0.56% | 💥 PoC | Aleapp CSV Mass Importer | 17/5/2025 | 17/6/2026 | The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.13% | — | Sidngr Import Export FOR Woocommerce | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2. | |
| Analizada | Media (6.1) | 0.33% | — | Cr1000 Affiliateimportereb | 15/5/2025 | 17/6/2026 | The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6.1) | 0.57% | 💥 Exploit | Cr1000 Affiliateimportereb | 15/5/2025 | 17/6/2026 | The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.2) | 0.57% | — | Michael Cannon Flickr Shortcode ImporterAI | 24/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This issue affects Flickr Shortcode Importer: from n/a through <= 2.2.3. | |
| Analizada | Media (5.4) | 0.28% | — | Vjinfotech WP Import Export Lite | 22/4/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpfactory Product Excel Import Export Bulk Edit FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from… | |
| Aplazada | Crítica (9.6) | 0.26% | — | Uncodethemes Ultra Demo ImporterAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5. | |
| Aplazada | Alta (8.8) | 1.2% | — | Webtoffee Import Export SuiteAI | 1/4/2025 | 17/6/2026 | The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.1) | 1.2% | — | Soflyy Import Export SuiteAI | 1/4/2025 | 17/6/2026 | The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Alta (7.2) | 0.89% | 💥 PoC | Webtoffee Product Import Export FOR Woocommerce | 26/3/2025 | 17/6/2026 | The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with… |