Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.18% | — | Simple User Meta EditorAI | 7/1/2026 | 30/9/2026 | The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Alta (8) | 0.56% | — | User-meta User MetaAI | 11/9/2025 | 17/6/2026 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the postInsertUserProcess function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.15% | — | ADD User MetaAI | 15/8/2025 | 17/6/2026 | The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'add-user-meta' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via… | |
| Aplazada | Alta (7.1) | 0.28% | — | Khaled User MetaAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Khaled User Meta user-meta allows Reflected XSS.This issue affects User Meta: from n/a through <= 3.1.2. | |
| Aplazada | Media (6.5) | 0.41% | — | User-meta User MetaAI | 9/11/2024 | 17/6/2026 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.1 via the getUser() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 1.1% | — | User-meta User MetaAI | 29/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0. | |
| Modificada | Media (5.4) | 0.36% | — | Display Post Meta, Term Meta, Comment Meta, AND User Meta Project Display Post Meta, Term Meta, Comment Meta, AND User Meta | 31/5/2023 | 17/6/2026 | The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.26% | — | User-meta User Meta Manager | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions. | |
| Modificada | Media (6.1) | 0.41% | — | User Meta Manager Project User Meta Manager | 23/4/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Jason Lau User Meta Manager plugin <= 3.4.9 versions. | |
| Modificada | Media (6.5) | 2.3% | — | User-meta User Meta User Profile Builder AND User Management | 8/6/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads | |
| Modificada | Media (4.8) | 0.59% | — | User-meta User Meta User Profile Builder AND User Management | 30/5/2022 | 17/6/2026 | The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.3) | 0.78% | — | User Meta Shortcodes Project User Meta Shortcodes | 13/12/2021 | 17/6/2026 | The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes |