Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | Wedevs WP User FrontendAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions. | |
| Recibida | Media (5.9) | 0.29% | — | Wedevs File UploadsAI | 5/10/2026 | 5/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly,… | |
| Aplazada | Media (4.3) | 0.18% | — | Wedevs WP User FrontendAI | 2/10/2026 | 2/10/2026 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted… | |
| Aplazada | Media (6.3) | 0.25% | — | Wedevs WP Project ManagerAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Wedevs WP ERPAI | 30/9/2026 | 30/9/2026 | Author SQL Injection in WP ERP <= 1.17.9 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Wedevs WP ERPAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. | |
| Aplazada | Alta (7.4) | 0.25% | — | Wedevs User FrontendAI | 30/9/2026 | 30/9/2026 | The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a… | |
| Aplazada | Media (6.5) | 0.47% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (4.3) | 0.29% | — | Wedevs EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wedevs WP Project ManagerAI | 24/8/2026 | 27/8/2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | |
| Aplazada | Alta (7.2) | 0.25% | — | Wedevs DokanAI | 21/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution… | |
| Aplazada | Media (6.5) | 0.42% | — | Wedevs EventinAI | 19/8/2026 | 26/8/2026 | The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users. | |
| Aplazada | Media (5.3) | 0.29% | — | Wedevs DokanAI | 6/8/2026 | 12/8/2026 | Custom role Broken Access Control in Dokan <= 5.0.10 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Wedevs DokanAI | 3/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the… | |
| Aplazada | Media (4.3) | 0.25% | — | Wedevs DokanAI | 3/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders… | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs User FrontendAI | 27/7/2026 | 27/7/2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads… | |
| Aplazada | Alta (7.1) | 0.29% | — | Wedevs Dokan PROAI | 23/7/2026 | 23/7/2026 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP ERPAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs Dokan PROAI | 23/7/2026 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7. | |
| Aplazada | Media (6.5) | 0.45% | — | Wedevs ERPAI | 9/7/2026 | 9/7/2026 | The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 1.17.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (5.3) | 0.42% | — | Wedevs User FrontendAI | 9/7/2026 | 9/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes… | |
| Aplazada | Media (4.3) | 0.35% | — | Wedevs WedocsAI | 3/7/2026 | 6/7/2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action,… |