Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.35% | — | Dev.institute Restrict User AccessAI | 2/9/2026 | 3/9/2026 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |
| Aplazada | Media (5.3) | 0.22% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Alta (8.8) | 0.41% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code… | |
| Aplazada | Alta (8.7) | 0.46% | — | Avideo User LocationAIWwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers… | |
| Pendiente de análisis | Alta (8.6) | 1.6% | — | Suse Yast2-usersAI | 1/9/2026 | 2/9/2026 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to… | |
| Aplazada | Media (6.1) | 0.38% | — | Codesmiths User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.33% | — | Codesigner User Profile BuilderAI | 1/9/2026 | 1/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Crítica (9.2) | 0.92% | — | Profilepress WP User AvatarAI | 31/8/2026 | 8/9/2026 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Custom User Registration Fields FOR WoocommerceAI | 29/8/2026 | 1/9/2026 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in… | |
| Aplazada | Alta (8.2) | 0.32% | — | Codesmiths User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other… | |
| Aplazada | Media (6.6) | 0.42% | 💥 PoC | Cozmoslabs User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is… | |
| Aplazada | Media (6.8) | 0.43% | — | User Profile BuilderAI | 29/8/2026 | 31/8/2026 | The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by… | |
| Aplazada | Crítica (9.8) | 0.28% | — | UIX UsercenterAI | 29/8/2026 | 31/8/2026 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated… | |
| Aplazada | Alta (7.2) | 0.46% | — | User Registration AND MembershipAI | 28/8/2026 | 28/8/2026 | The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change… | |
| Aplazada | Media (4.3) | 0.25% | — | User Registration MembershipAI | 28/8/2026 | 28/8/2026 | The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an… | |
| Aplazada | Media (5.3) | 0.25% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |
| Aplazada | Alta (7.2) | 0.52% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable… | |
| Aplazada | Alta (7.5) | 0.66% | — | Onedesigns ONE User AvatarAI | 28/8/2026 | 28/8/2026 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in wp_handle_upload() called without a MIME allow-list, with… | |
| Aplazada | Alta (8.8) | 0.73% | — | Silverstripe UserformsAISilverstripe CMSAI | 27/8/2026 | 9/9/2026 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to… | |
| Aplazada | Media (5.3) | 0.29% | — | Mycred NEW User ApproveAI | 20/8/2026 | 24/8/2026 | Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8. | |
| Aplazada | Crítica (9.8) | 0.61% | — | User Registration Membership PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | |
| Aplazada | Alta (7.5) | 0.44% | — | Pickplugins User VerificationAI | 19/8/2026 | 26/8/2026 | The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them,… | |
| Aplazada | Media (4.9) | 0.48% | — | User Login HistoryAI | 16/8/2026 | 20/8/2026 | The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 3.9% | 💥 Exploit | User Profile BuilderAI | 15/8/2026 | 20/8/2026 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is… |