Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.82% | — | Rarathemes Rara ONE Click Demo ImportAI | 9/9/2026 | 10/9/2026 | Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wp_handle_upload() that disables WordPress core's file type validation checks across… | |
| Aplazada | Alta (7.2) | 0.50% | — | Demo ImportAI | 1/8/2026 | 26/8/2026 | The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the… | |
| Aplazada | Media (5.9) | 0.24% | — | Hashthemes Demo ImporterAI | 23/7/2026 | 23/7/2026 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | |
| Aplazada | Media (4.3) | 0.43% | — | Catchthemes Catch Themes Demo ImportAI | 16/7/2026 | 17/7/2026 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling Plugin_Upgrader::install() to download… | |
| Aplazada | Media (5.3) | 0.31% | — | Themegrill Demo ImporterAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6. | |
| Aplazada | Media (5.4) | 0.20% | — | Mizan Themes Mizan Demo ImporterAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3. | |
| Aplazada | Alta (7.5) | 0.43% | — | Kraftplugins Demo Importer PlusAI | 17/1/2026 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable… | |
| Aplazada | Media (4.3) | 0.18% | — | Kraftplugins Demo Importer PlusAI | 30/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8. | |
| Aplazada | Alta (8.8) | 0.35% | — | Kraftplugins Demo Importer PlusAI | 18/12/2025 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.27% | — | Blaze Demo ImporterAI | 12/12/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with subscriber level… | |
| Aplazada | Alta (8.8) | 0.55% | — | Kraftplugins Demo Importer PlusAI | 5/12/2025 | 25/9/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Aplazada | Media (6.5) | 0.34% | — | Codexthemes Thegem Demo ImportAI | 6/11/2025 | 5/10/2026 | Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects TheGem Demo Import (for WPBakery): from n/a through <= 5.10.5. | |
| Aplazada | Media (5.4) | 0.28% | — | Themeshopy TS Demo ImporterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Demo Importer: from n/a through <= 0.1.3. | |
| Aplazada | Alta (7.2) | 0.69% | — | Demo Import KITAI | 15/10/2025 | 17/6/2026 | The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.1.0 via the import functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.24% | — | Blaze Demo ImporterAI | 16/9/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Alta (8.8) | 0.59% | — | Axlethemes Axle Demo Importer | 10/6/2025 | 17/6/2026 | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server | |
| Aplazada | Crítica (9.6) | 0.26% | — | Uncodethemes Ultra Demo ImporterAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5. | |
| Aplazada | Alta (7.2) | 1.8% | — | Crafthemes Demo ImportAI | 14/12/2024 | 17/6/2026 | The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload… | |
| Aplazada | Alta (8.8) | 0.42% | — | Stackthemes Bstone Demo ImporterAI | 29/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects Bstone Demo Importer: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.9) | 0.58% | — | Themegrill Demo ImporterAI | 16/10/2024 | 17/6/2026 | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named… | |
| Analizada | Media (5.4) | 0.32% | — | Sigmadevs Easy Demo Importer | 4/10/2024 | 17/6/2026 | The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.32% | — | Kraftplugins Demo Importer Plus | 2/10/2024 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Alta (7.5) | 0.39% | — | Olivethemes Olive ONE Click Demo Import | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2. | |
| Modificada | Media (6.5) | 0.50% | — | Wpneuron Sparkle Demo Importer | 22/6/2024 | 17/6/2026 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Alta (7.6) | 0.33% | — | Crafthemes Demo ImportAI | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crafthemes Demo Import: from n/a through <= 3.3. |