Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | 0.22% | — | ProfilepressAI | 3/10/2026 | 3/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input… | |
| Recibida | Alta (8.8) | 0.63% | — | ProfilepressAI | 3/10/2026 | 3/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 0.65% | — | ProfilepressAI | 19/9/2026 | 21/9/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not… | |
| Aplazada | Media (5.5) | 0.43% | — | Zyx0814 FilepressAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql injection. The attack can be launched remotely. The exploit is publicly available and… | |
| Aplazada | Crítica (9.2) | 0.92% | — | Profilepress WP User AvatarAI | 31/8/2026 | 8/9/2026 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a… | |
| Aplazada | Media (6.5) | 0.31% | — | ProfilepressAI | 21/8/2026 | 26/8/2026 | The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date. | |
| Aplazada | Media (5.4) | 0.52% | — | ProfilepressAI | 16/8/2026 | 20/8/2026 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not… | |
| Aplazada | Alta (8.8) | 1.1% | — | ProfilepressAI | 17/7/2026 | 17/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an… | |
| Aplazada | Media (6.5) | 0.22% | — | ProfilepressAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions. | |
| Aplazada | Media (5.5) | 0.45% | — | Zyx0814 FilepressAI | 8/5/2026 | 17/6/2026 | A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (4.3) | 0.36% | — | ProfilepressAI | 15/4/2026 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not properly enforcing the plan active… | |
| Aplazada | Media (6.5) | 0.38% | — | ProfilepressAI | 4/4/2026 | 24/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the… | |
| Aplazada | Alta (7.1) | 0.31% | — | ProfilepressAI | 4/4/2026 | 21/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the… | |
| Aplazada | Alta (8.1) | 0.50% | — | ProfilepressAI | 11/3/2026 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts a user-controlled… | |
| Aplazada | Media (5.4) | 0.48% | — | ProfilepressAI | 9/12/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the `type` parameter in the form preview… | |
| Aplazada | Media (6.5) | 0.44% | — | ProfilepressAI | 16/8/2025 | 17/6/2026 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not… | |
| Analizada | Baja (3.5) | 0.32% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Media (4.8) | 0.31% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Media (4.8) | 0.36% | — | Properfraction Profilepress | 13/2/2025 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Analizada | Media (4.8) | 0.35% | — | Properfraction Profilepress | 12/12/2024 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… | |
| Analizada | Media (4.8) | 0.35% | — | Properfraction Profilepress | 12/12/2024 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when… | |
| Analizada | Media (5.3) | 0.41% | — | Properfraction Profilepress | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1. | |
| Modificada | Media (5.3) | 0.50% | — | Properfraction Profilepress | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through <= 4.13.2. | |
| Analizada | Media (5.3) | 0.41% | — | Properfraction Profilepress | 27/11/2024 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as… | |
| Analizada | Crítica (9.8) | 0.53% | — | Properfraction Profilepress | 23/10/2024 | 17/6/2026 | The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site,… |