Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Wedevs WP User FrontendAI | 2/10/2026 | 2/10/2026 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted… | |
| Aplazada | Media (6.5) | 0.47% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpusermanager WP User ManagerAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpusermanager WP User ManagerAI | 22/9/2026 | 22/9/2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Crítica (9.2) | 0.92% | — | Profilepress WP User AvatarAI | 31/8/2026 | 8/9/2026 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Wpusermanager WP User ManagerAI | 15/6/2026 | 17/6/2026 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | |
| Aplazada | Alta (7.5) | 2.7% | — | Wpusermanager WP User ManagerAI | 6/6/2026 | 23/7/2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server,… | |
| Aplazada | Media (6.5) | 0.41% | — | Libwww-perl LWP UseragentAI | 12/5/2026 | 17/6/2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5. | |
| Aplazada | Media (5.4) | 0.11% | — | Simple-membership-plugin Simple Membership WP User ImportAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1. | |
| Aplazada | Media (5.3) | 0.90% | — | Wedevs WP User FrontendAI | 2/1/2026 | 17/6/2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,… | |
| Aplazada | Media (6.8) | 0.82% | — | Wpusermanager WP User ManagerAI | 12/12/2025 | 17/6/2026 | The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Wpusermanager WP User ManagerAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12. | |
| Aplazada | Media (5.4) | 0.23% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.4) | 0.27% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Alta (7.1) | 0.13% | — | Vgstef WP User Stylesheet SwitcherAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affects WP User Stylesheet Switcher: from n/a through <= v2.2.0. | |
| Aplazada | Media (4.3) | 0.28% | — | Wpeventmanager WP User Profile AvatarAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6. | |
| Aplazada | Alta (8.1) | 0.81% | — | Wedevs WP User FrontendAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Alta (8.8) | 0.92% | — | WP User Frontend PROAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on… |