Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Ntzapps CRM Memberships | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <= 1.6 versions. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wclovers Wcfm Membership | 20/5/2023 | 17/6/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system… | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Membership Database Project Membership Database | 8/5/2023 | 17/6/2026 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.32% | — | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing… | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying… | |
| Modificada | Crítica (9.8) | 2.1% | 💥 PoC | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the… | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Alta (8.8) | 60% | — | Strangerstudios Paid Memberships PRO | 20/3/2023 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. | |
| Modificada | Media (5.4) | 65% | — | Strangerstudios Paid Memberships PRO | 13/2/2023 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | Wpswings Membership FOR Woocommerce | 30/1/2023 | 17/6/2026 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. | |
| Modificada | Crítica (9.8) | 92% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 20/1/2023 | 17/6/2026 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | |
| Modificada | Media (5.4) | 0.53% | — | Simple-membership-plugin Simple Membership | 16/1/2023 | 17/6/2026 | The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (4.9) | 0.88% | — | Simple-membership-plugin Simple Membership WP User Import | 12/1/2023 | 17/6/2026 | The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional… | |
| Modificada | Media (6.1) | 0.62% | — | Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core | 16/9/2022 | 17/6/2026 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected… | |
| Modificada | Crítica (9.8) | 1.4% | — | Simple-membership-plugin Simple Membership | 1/8/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Simple-membership-plugin Simple Membership | 1/8/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Simple-membership-plugin Simple Membership | 13/6/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.60% | — | Contextureintl Page Security & Membership | 18/4/2022 | 17/6/2026 | The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 0.53% | — | Simple-membership-plugin Simple Membership | 21/3/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack | |
| Modificada | Media (4.7) | 0.47% | — | Simple-membership-plugin Simple Membership | 28/2/2022 | 17/6/2026 | The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 7/2/2022 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Membership System Using PHP AND Ajax Project Simple Membership System Using PHP AND Ajax | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Strangerstudios Paid Memberships PRO | 27/12/2021 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.0% | — | Profilepress User Registration, Login Form, User Profile & Membership | 13/12/2021 | 17/6/2026 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue |