Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Alta (8.8) | 0.44% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 5/10/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of… | |
| Modificada | Alta (8.8) | 0.87% | — | Webmedia BAN Users | 13/9/2023 | 17/6/2026 | The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify the… | |
| Modificada | Media (4.3) | 0.48% | — | Riverforest-wp ALL Users Messenger | 30/8/2023 | 17/6/2026 | The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger. | |
| Modificada | Media (4.3) | 0.74% | — | Froger WP Remote Users Sync | 16/8/2023 | 17/6/2026 | The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to… | |
| Modificada | Media (5.4) | 0.73% | — | Froger WP Remote Users Sync | 16/8/2023 | 17/6/2026 | The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from… | |
| Modificada | Alta (7.2) | 0.93% | — | Webtoffee Import Export Wordpress Users | 18/7/2023 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop… | |
| Modificada | Alta (8.8) | 0.32% | — | Etoilewebdesign Front END Users | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Mass Email TO Users | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <= 1.1.4 versions. | |
| Modificada | Media (4.8) | 0.41% | — | Usersnap | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions. | |
| Modificada | Media (6.1) | 0.47% | — | Qt-users Silk | 20/2/2023 | 17/6/2026 | A vulnerability was found in qt-users-jp silk 0.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file contents/root/examples/header.qml. The manipulation of the argument model.key/model.value leads to cross site scripting. The attack can be initiated remotely. The name of the… | |
| Modificada | Media (6.1) | 0.49% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 0.33% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.45% | — | Change Password FOR Frontend Users Project Change Password FOR Frontend Users | 14/12/2022 | 17/6/2026 | An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed. | |
| Modificada | Alta (8) | 1.1% | — | Codection Import AND Export Users AND Customers | 7/11/2022 | 17/6/2026 | The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. | |
| Modificada | Media (4.2) | 0.42% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce | |
| Modificada | Alta (7.2) | 1.1% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (8.8) | 1.5% | — | Wp-users-exporter Project Wp-users-exporter | 6/9/2022 | 17/6/2026 | The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the… | |
| Modificada | Alta (7.2) | 1.3% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 27/6/2022 | 17/6/2026 | The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks | |
| Modificada | Media (4.8) | 0.67% | — | Miniorange Login Using Wordpress Users | 27/6/2022 | 17/6/2026 | The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.53% | — | Email Users Project Email Users | 13/6/2022 | 17/6/2026 | The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users | |
| Modificada | Media (4.8) | 0.71% | — | Codection Import AND Export Users AND Customers | 2/5/2022 | 17/6/2026 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (4.8) | 0.61% | — | Anmari AMR Users | 25/4/2022 | 17/6/2026 | The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 8.3% | 💥 Exploit | Usersultra Users Ultra | 25/4/2022 | 17/6/2026 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection. | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Techspawn Wp-email-users | 14/3/2022 | 17/6/2026 | The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks. |