Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Choose User Role AT RegistrationAI | 17/9/2026 | 18/9/2026 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation… | |
| Aplazada | Media (4.3) | 0.20% | — | Remove Meta Boxes PER User RoleAI | 2/6/2026 | 22/7/2026 | The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset… | |
| Aplazada | Media (5.3) | 0.28% | — | Hide Category BY User RoleAI | 27/11/2025 | 17/6/2026 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.1. This is due to a missing capability check on the admin_init hook that executes wp_cache_flush(). This makes it possible for unauthenticated attackers to flush the… | |
| Aplazada | Alta (7.5) | 0.43% | — | Premmerce User RolesAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows PHP Local File Inclusion.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Aplazada | Media (5.9) | 0.18% | — | Premmerce User RolesAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Stored XSS.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Aplazada | Media (4.3) | 0.25% | — | Premmerce User RolesAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.13. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpfront User Role EditorAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Mahabub81 User Roles AND CapabilitiesAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in mahabub81 User Roles and Capabilities user-roles-and-capabilities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Roles and Capabilities: from n/a through <= 1.2.6. | |
| Aplazada | Alta (8.8) | 0.25% | — | Wpfront User Role EditorAI | 8/4/2025 | 17/6/2026 | The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the whitelist_options() function. This makes it possible for unauthenticated attackers to update the default role option… | |
| Aplazada | Alta (7.1) | 0.39% | — | Bestwebsoft User RoleAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role user-roles allows Reflected XSS.This issue affects User Role: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.29% | — | Themesupport Hide Category BY User Role FOR WoocommerceAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Alta (8.8) | 0.25% | — | Krishankakkar Gap-hub-user-roleAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in krishankakkar gap-hub-user-role gap-hub-user-role allows Authentication Bypass.This issue affects gap-hub-user-role: from n/a through <= 3.4.1. | |
| Aplazada | Alta (8.8) | 0.33% | — | User Role EditorAI | 17/12/2024 | 17/6/2026 | The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or remove roles for arbitrary users,… | |
| Aplazada | Alta (8.1) | 0.61% | — | Premmerce User RolesAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.12. | |
| Modificada | Media (4.3) | 0.52% | — | Wpfront User Role Editor | 2/4/2024 | 17/6/2026 | The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Alta (8.8) | 0.41% | — | Bestwebsoft User Role | 3/4/2023 | 17/6/2026 | The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role. | |
| Modificada | Media (6.5) | 0.35% | — | Addify Automatic User Roles Switcher | 31/10/2022 | 17/6/2026 | The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator | |
| Modificada | Media (4.8) | 0.55% | — | ADD User Role Project ADD User Role | 9/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1 at WordPress. | |
| Modificada | Media (6.1) | 0.80% | — | Wpfront User Role Editor | 27/12/2021 | 17/6/2026 | The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.4% | — | Bestwebsoft User Role | 20/8/2019 | 17/6/2026 | The user-role plugin before 1.5.6 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… |