Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (4.3) | — | — | Wedevs WP User FrontendAI | 2/10/2026 | 2/10/2026 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted… | |
| Aplazada | Media (5.3) | 0.22% | — | User FrontendAI | 30/9/2026 | 30/9/2026 | The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role. | |
| Aplazada | Alta (7.4) | 0.25% | — | Wedevs User FrontendAI | 30/9/2026 | 30/9/2026 | The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a… | |
| Aplazada | Media (6.5) | 0.47% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Alta (8.8) | 0.41% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code… | |
| Aplazada | Media (5.3) | 0.25% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |
| Aplazada | Alta (7.2) | 0.52% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable… | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs User FrontendAI | 27/7/2026 | 27/7/2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads… | |
| Aplazada | Media (5.3) | 0.42% | — | Wedevs User FrontendAI | 9/7/2026 | 9/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes… | |
| Aplazada | Media (5.3) | 0.31% | — | User FrontendAI | 8/7/2026 | 8/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Media (4.3) | 0.26% | — | Weplugins User FrontendAI | 9/6/2026 | 23/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Alta (8.8) | 1.3% | — | Wedevs User FrontendAI | 8/5/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Wedevs WP User FrontendAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5. | |
| Aplazada | Media (5.3) | 0.19% | — | User FrontendAI | 16/3/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.55% | — | Wedevs User FrontendAI | 26/2/2026 | 17/6/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext'… | |
| Aplazada | Media (5.3) | 0.90% | — | Wedevs WP User FrontendAI | 2/1/2026 | 17/6/2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,… | |
| Aplazada | Media (5.4) | 0.23% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.4) | 0.27% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12. |