Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.18%—Wedevs WP User FrontendAI2/10/20262/10/2026
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted…
AplazadaMedia (5.3)0.22%—User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role.
AplazadaAlta (7.4)0.25%—Wedevs User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a…
AplazadaAlta (7.2)0.25%—Frontend Post Submission Manager LiteAI30/9/202630/9/2026
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes…
AplazadaMedia (6.5)0.47%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (5.3)0.25%—Wedevs WP User FrontendAI23/9/202623/9/2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (6.5)0.34%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaCrítica (9.8)0.44%—Metabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI22/9/202622/9/2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET…
AplazadaAlta (8.3)0.36%—Zabbix FrontendAI13/9/202624/9/2026
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing…
AplazadaCrítica (9.8)0.91%—Dynamiapps Frontend AdminAI6/9/20268/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its…
AplazadaMedia (5.9)0.38%—Dynamiapps Frontend AdminAI4/9/20268/9/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the…
AplazadaMedia (5.3)0.22%—User FrontendAI2/9/20263/9/2026
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to…
AplazadaAlta (8.8)0.52%—Wedevs WP User FrontendAI2/9/20262/9/2026
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
AplazadaAlta (8.8)0.41%—User FrontendAI2/9/20263/9/2026
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code…
AplazadaAlta (7.5)0.96%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can…
AplazadaMedia (6.4)0.20%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaMedia (4.3)0.25%—Dynamiapps Frontend AdminAI29/8/202631/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
AplazadaMedia (5.3)0.25%—User FrontendAI28/8/202628/8/2026
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
AplazadaAlta (7.2)0.52%—User FrontendAI28/8/202628/8/2026
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable…
AplazadaMedia (6.5)0.22%—Dynamiapps Frontend AdminAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
AplazadaCrítica (9.8)0.84%—Dynamiapps Frontend AdminAI16/8/202620/8/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the…
AplazadaAlta (8.8)0.59%—Dynamiapps Frontend AdminAI11/8/202612/8/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above…
AplazadaCrítica (9.8)0.55%—Dynamiapps Frontend AdminAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
AplazadaMedia (5.4)0.13%—Najeebmedia Frontend File ManagerAI2/8/202626/8/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,…
AplazadaAlta (8.8)0.45%—Dynamiapps Frontend AdminAI31/7/202626/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output…