Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.27% | — | Biplob018 Team Showcase AND Slider Team Members BuilderAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biplob018 Team Showcase and Slider – Team Members Builder team-showcase-ultimate allows Reflected XSS.This issue affects Team Showcase and Slider – Team Members Builder: from n/a through <= 1.3. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wpmembership WP MembershipAI | 9/11/2024 | 17/6/2026 | The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Modificada | Crítica (9.8) | 0.43% | — | Caseproof Memberpress | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34. | |
| Analizada | Crítica (9.8) | 0.67% | — | Strangerstudios Paid Memberships PRO | 1/11/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | |
| Aplazada | Alta (7.7) | 0.62% | — | Wishlistmember Wishlist Member XAI | 1/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Traversal.This issue affects WishList Member X: from n/a through 3.26.6. | |
| Aplazada | Alta (8.2) | 0.36% | — | Wishlistmember Wishlist Member XAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WishList Member X: from n/a through 3.26.6 | |
| Aplazada | Media (6.4) | 0.34% | — | WP Team Wordpress Team Member PluginAI | 30/10/2024 | 17/6/2026 | The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's htteamember shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (6.1) | 0.31% | — | Rimonhabib BP Member Type Manager | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager bp-member-type-manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through <= 1.01. | |
| Analizada | Media (5.4) | 0.45% | — | Butlerblog Wp-members | 25/10/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.27% | — | Simple-membership-plugin Simple Membership | 24/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affects Simple Membership: from n/a through <= 4.5.3. | |
| Analizada | Media (6.1) | 0.47% | — | Butlerblog Wp-members | 22/10/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.4) | 0.32% | — | Codeastro Membership Management System | 21/10/2024 | 17/6/2026 | CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php | |
| Analizada | Media (5.4) | 0.30% | — | Codeastro Membership Management System | 21/10/2024 | 17/6/2026 | CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php. | |
| Analizada | Crítica (9.8) | 0.53% | — | Najeebmedia Memberhero | 20/10/2024 | 11/8/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7. | |
| Modificada | Alta (8.8) | 0.42% | — | Themexpo Rs-members | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.8) | 0.50% | — | Taketin TO WP MembershipAI | 16/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17. | |
| Aplazada | Media (6.3) | 0.35% | — | Indeed Membership PROAI | 16/10/2024 | 17/6/2026 | The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Wpindeed Ultimate Membership PROAI | 16/10/2024 | 17/6/2026 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
| Aplazada | Media (4.7) | 0.33% | — | Wp.insider Simple Membership After Login RedirectionAI | 10/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a through <= 1.6. | |
| Modificada | Media (6.1) | 0.33% | — | Wpcom Member | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lomu WPCOM Member wpcom-member allows Reflected XSS.This issue affects WPCOM Member: from n/a through <= 1.5.4. | |
| Analizada | Media (5.4) | 0.32% | — | Memberful | 4/10/2024 | 17/6/2026 | The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up to, and including, 1.73.7 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Media (4.3) | 0.34% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook… | |
| Analizada | Media (5.4) | 0.44% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output… | |
| Analizada | Media (6.1) | 0.39% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 2/10/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for… | |
| Analizada | Alta (8.6) | 0.44% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. |