User Registration Membership
User Registration Membership: vulnerabilidades y CVE
User Registration Membership tiene 19 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86407 | Baja (3.7) | 0.28% | — | 13 sept 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase… |
| CVE-2026-86406 | Alta (7.5) | 0.32% | — | 13 sept 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing… |
| CVE-2026-80072 | Media (4.7) | 0.29% | — | 13 sept 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary… |
| CVE-2026-80071 | Alta (7.2) | 0.46% | — | 13 sept 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with… |
| CVE-2026-79995 | Media (4.3) | 0.25% | — | 28 ago 2026 | The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with… |
| CVE-2026-16736 | Alta (7.5) | 0.41% | — | 5 ago 2026 | The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new… |
| CVE-2026-11966 | Media (5.3) | 0.30% | — | 17 jul 2026 | The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier,… |
| CVE-2026-11964 | Crítica (9.1) | 0.45% | — | 13 jul 2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a… |
| CVE-2026-11965 | Media (6.5) | 0.27% | — | 2 jul 2026 | The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account… |
| CVE-2026-6145 | Media (5.3) | 0.43% | — | 14 may 2026 | The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the… |
| CVE-2026-3601 | Media (4.3) | 0.35% | — | 5 may 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including,… |
| CVE-2026-6203 | Media (6.1) | 0.56% | — | 13 abr 2026 | The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the… |
| CVE-2026-1865 | Media (6.5) | 0.31% | — | 8 abr 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the… |
| CVE-2026-4056 | Media (5.4) | 0.30% | — | 24 mar 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through… |
| CVE-2026-1492 | Crítica (9.8) | 28% | — | 3 mar 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all… |
| CVE-2026-1779 | Alta (8.1) | 0.36% | — | 26 feb 2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This… |
| CVE-2025-14976 | Media (5.4) | 0.15% | — | 10 ene 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… |
| CVE-2025-9085 | Media (4.9) | 0.34% | — | 6 sept 2025 | The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient… |
| CVE-2025-3281 | Media (5.3) | 0.42% | — | 6 may 2025 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.