Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.27% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.28% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled. | |
| Aplazada | Alta (7.5) | 0.34% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review… | |
| Aplazada | Alta (7.5) | 0.34% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is… | |
| Aplazada | Alta (7.5) | 0.25% | — | Wpmet WP Ultimate ReviewAI | 3/10/2026 | 6/10/2026 | The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying… | |
| Aplazada | Alta (8.1) | 0.36% | — | Wpmet WP Ultimate ReviewAI | 22/9/2026 | 22/9/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.26% | — | Wpmet WP Ultimate ReviewAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wp Ultimate Review: from n/a through <= 2.3.8. | |
| Aplazada | Media (6.5) | 0.24% | — | Wpmet WP Ultimate ReviewAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7. | |
| Aplazada | Alta (7.1) | 0.39% | — | Jtibbles WP Ultimate Reviews FreeAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jtibbles WP Ultimate Reviews FREE wp-ultimate-reviews-free allows Reflected XSS.This issue affects WP Ultimate Reviews FREE: from n/a through <= 1.0.2. | |
| Analizada | Media (5.3) | 0.39% | — | Wpmet WP Ultimate Review | 17/5/2024 | 17/6/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5. | |
| Modificada | Alta (7.5) | 0.48% | — | Wpmet WP Ultimate Review | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing.This issue affects Wp Ultimate Review: from n/a through <= 2.3.6. | |
| Modificada | Alta (7.5) | 0.39% | — | Wpmet WP Ultimate Review | 22/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5. | |
| Modificada | Alta (7.5) | 0.46% | — | Wpmet WP Ultimate Review | 19/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpmet WP Ultimate Review | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpmet WP Ultimate Review | 22/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpmet WP Ultimate Review | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. |