Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Wedevs WP User FrontendAI | 2/10/2026 | 2/10/2026 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted… | |
| Aplazada | Media (6.5) | 0.47% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5. | |
| Aplazada | Media (5.3) | 0.90% | — | Wedevs WP User FrontendAI | 2/1/2026 | 17/6/2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,… | |
| Aplazada | Media (5.4) | 0.23% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.4) | 0.27% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Alta (8.1) | 0.81% | — | Wedevs WP User FrontendAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Alta (8.8) | 0.92% | — | WP User Frontend PROAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (4.3) | 0.31% | — | Wedevs WP User FrontendAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8. | |
| Analizada | Alta (7.2) | 0.44% | — | Wedevs WP User Frontend | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7. | |
| Aplazada | Alta (7.2) | 0.64% | — | Wedevs WP User FrontendAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5. | |
| Modificada | Crítica (9.8) | 0.69% | — | Wedevs WP User Frontend | 21/11/2022 | 17/6/2026 | The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary… | |
| Modificada | Alta (8.8) | 17% | — | Wedevs WP User Frontend | 24/1/2022 | 17/6/2026 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting |