Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.22%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaAlta (8.8)0.33%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
AnalizadaMedia (5.9)0.33%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (5.4)0.40%—Tipsandtricks-hq WP Emember13/7/202417/6/2026
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9.8)0.54%—Wishlistmember Wishlist Member XAI10/7/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
AplazadaAlta (7.5)0.55%—Wishlistmember Wishlist Member XAI10/7/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
ModificadaAlta (7.2)0.74%—Strangerstudios Paid Memberships PRO9/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
ModificadaCrítica (9.8)0.49%—Wishlist Member9/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
ModificadaAlta (7.5)0.46%—Wishlistmember Wishlist Member X24/6/202417/6/2026
Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
ModificadaAlta (8.8)0.53%—Wishlistmember Wishlist Member24/6/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.
ModificadaAlta (8.8)0.42%—Wishlistmember Wishlist Member X24/6/202417/6/2026
Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.
AplazadaMedia (6.3)0.17%—Armember PremiumAI22/6/202417/6/2026
The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options…
AnalizadaAlta (8.8)0.48%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
AplazadaAlta (8.2)0.44%—Paidmembershipspro Ccbill GatewayAI19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.
ModificadaMedia (5.4)0.22%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.36%—Themekraft Buddypress Woocommerce MY Account Integration. Create Woocommerce Member Pages10/6/202417/6/2026
Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.
ModificadaMedia (5.3)0.44%—Membersonly Buddypress Members Only6/6/202417/6/2026
The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be Opened to Guest" feature (when unset) and…
AnalizadaAlta (8.8)0.39%—Reputeinfosystems Armember4/6/202417/6/2026
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
AnalizadaAlta (8.3)0.44%—Tipsandtricks-hq WP Emember4/6/202417/6/2026
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.4)0.29%—Caseproof Memberpress22/5/202417/6/2026
The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating…
ModificadaMedia (5.4)0.26%—Caseproof Memberpress22/5/202417/6/2026
The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaAlta (7.5)0.42%—WP Sharks S2member PROAI17/5/202417/6/2026
Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.
AnalizadaAlta (8.8)0.55%—Reputeinfosystems Armember17/5/202417/6/2026
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
AnalizadaCrítica (9.8)0.77%—Simple-membership-plugin Simple Membership17/5/202417/6/2026
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
AnalizadaAlta (8.8)0.91%—Simple-membership-plugin Simple Membership17/5/202417/6/2026
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
Orbitaley — Vulnerabilidades