Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.22% | — | Ultimate Multi Design Video CarouselAI | 3/10/2025 | 17/6/2026 | The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts… | |
| Aplazada | Media (4.3) | 0.13% | — | Ultimate Viral QuizAI | 3/10/2025 | 17/6/2026 | The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on thesave_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Modificada | Media (6.1) | 0.23% | 💥 PoC | Fairsketch Rise Ultimate Project Manager | 29/9/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders. | |
| Aplazada | Media (4.3) | 0.27% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Retrieve Embedded Sensitive Data.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Themepoints Carousel UltimateAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate carousel allows Stored XSS.This issue affects Carousel Ultimate: from n/a through <= 1.8. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes Ultimate Store KITAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Mantrabrain Ultimate WatermarkAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in MantraBrain Ultimate Watermark ultimate-watermark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Watermark: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Rustaurius Ultimate WP MailAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Stored XSS.This issue affects Ultimate WP Mail: from n/a through <= 1.3.8. | |
| Aplazada | Alta (8.8) | 0.75% | — | WP Import Ultimate CSV XML ImporterAI | 17/9/2025 | 25/9/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.15% | — | Ultimate BlogrollAI | 12/9/2025 | 17/6/2026 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… | |
| Aplazada | Media (4.3) | 0.24% | — | Webcodingplace Ultimate Classified ListingsAI | 11/9/2025 | 17/6/2026 | The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all versions up to, and including, 1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change… | |
| Aplazada | Alta (7.5) | 0.59% | — | Webcodingplace Ultimate Classified ListingsAI | 11/9/2025 | 25/9/2026 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_dashboard' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the… | |
| Aplazada | Alta (7.2) | 0.25% | — | Fwdesign Ultimate Video PlayerAI | 9/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= 10.1. | |
| Aplazada | Crítica (9.3) | 0.62% | — | Wpswings Woocommerce Ultimate Gift CardAI | 9/9/2025 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Blind SQL Injection.This issue affects WooCommerce Ultimate Gift Card: from n/a through <= 2.9.6. | |
| Aplazada | Alta (7.1) | 0.13% | — | Samer Bechara Ultimate Ajax LoginAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login ultimate-ajax-login allows Reflected XSS.This issue affects Ultimate AJAX Login: from n/a through <= 1.2.1. | |
| Aplazada | Media (5.9) | 0.22% | — | Themepoints Carousel UltimateAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Carousel Ultimate carousel allows Stored XSS.This issue affects Carousel Ultimate: from n/a through <= 1.8. | |
| Aplazada | Media (5.9) | 0.22% | — | Wpcodeus Ultimate Client DashAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Ultimate Client Dash ulimate-client-dash allows Stored XSS.This issue affects Ultimate Client Dash: from n/a through <= 4.7. | |
| Aplazada | Media (4.3) | 0.13% | — | Ultimate TAG Warrior ImporterAI | 29/8/2025 | 17/6/2026 | The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site… | |
| Aplazada | Alta (7.1) | 0.13% | — | Ultimate Twitter Profile WidgetAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Fwdesign Ultimate Video PlayerAI | 15/8/2025 | 17/6/2026 | Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Video Player: from n/a through <= 10.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 2/8/2025 | 17/6/2026 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.50% | — | Ultimatefosters UltimateposAI | 31/7/2025 | 17/6/2026 | A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due to the lack of proper validation of user inputs via ‘/products/<PRODUCT_ID>/edit’, affecting to ‘name’ parameter via POST. The vulnerability could allow a remote attacker to send a specially crafted… | |
| Aplazada | Media (6.4) | 0.23% | — | Shortcodes UltimateAI | 22/7/2025 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.1) | 0.17% | — | Shortcodes UltimateAI | 21/7/2025 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes… |