Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

111 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.1)——Wedevs WP User FrontendAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
RecibidaMedia (5.9)0.29%—Wedevs File UploadsAI5/10/20265/10/2026
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly,…
AplazadaMedia (4.3)0.18%—Wedevs WP User FrontendAI2/10/20262/10/2026
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted…
AplazadaMedia (6.3)0.25%—Wedevs WP Project ManagerAI1/10/20261/10/2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
AplazadaAlta (7.6)0.28%—Wedevs WP ERPAI30/9/202630/9/2026
Author SQL Injection in WP ERP <= 1.17.9 versions.
AplazadaAlta (7.2)0.37%—Wedevs WP ERPAI30/9/202630/9/2026
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
AplazadaAlta (7.4)0.25%—Wedevs User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a…
AplazadaMedia (6.5)0.47%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (5.3)0.25%—Wedevs WP User FrontendAI23/9/202623/9/2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (6.5)0.34%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (4.3)0.29%—Wedevs EventinAI9/9/20269/9/2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaAlta (8.8)0.52%—Wedevs WP User FrontendAI2/9/20262/9/2026
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
AplazadaCrítica (9.8)0.56%—Wedevs WP Project ManagerAI24/8/202627/8/2026
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
AplazadaAlta (7.2)0.25%—Wedevs DokanAI21/8/202626/8/2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution…
AplazadaMedia (6.5)0.42%—Wedevs EventinAI19/8/202626/8/2026
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
AplazadaMedia (5.3)0.29%—Wedevs DokanAI6/8/202612/8/2026
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
AplazadaMedia (4.3)0.25%—Wedevs DokanAI3/8/202626/8/2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the…
AplazadaMedia (4.3)0.25%—Wedevs DokanAI3/8/202626/8/2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders…
AplazadaMedia (6.5)0.34%—Wedevs User FrontendAI27/7/202627/7/2026
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads…
AplazadaAlta (7.1)0.29%—Wedevs Dokan PROAI23/7/202623/7/2026
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
AplazadaMedia (6.5)0.34%—Wedevs WP ERPAI23/7/202623/7/2026
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
AplazadaAlta (7.1)0.25%—Wedevs Dokan PROAI23/7/202621/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7.
AplazadaMedia (6.5)0.45%—Wedevs ERPAI9/7/20269/7/2026
The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 1.17.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
AplazadaMedia (5.3)0.42%—Wedevs User FrontendAI9/7/20269/7/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes…
AplazadaMedia (4.3)0.35%—Wedevs WedocsAI3/7/20266/7/2026
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action,…