Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.43% | — | Simple-membership-plugin Simple Membership | 14/5/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.53% | — | ArmemberAI | 2/5/2024 | 17/6/2026 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on the redirect url supplied via the redirect_to parameter. This makes it possible… | |
| Modificada | Media (4.3) | 0.30% | — | Strangerstudios Paid Memberships PRO | 2/5/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it… | |
| Modificada | Media (5.4) | 0.50% | — | Ultimatemember Ultimate Member | 2/5/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output… | |
| Aplazada | Media (5.3) | 0.50% | — | Butlerblog Wp-membersAI | 26/4/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.34% | — | Simple-membership-plugin Simple Membership | 25/4/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.24% | — | Strangerstudios Paid Memberships PRO | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. | |
| Modificada | Alta (8.8) | 0.23% | — | Strangerstudios Paid Memberships PRO | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. | |
| Aplazada | Media (4.3) | 0.20% | — | Cozmoslabs Paid Member SubscriptionsAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0. | |
| Modificada | Crítica (9.1) | 0.57% | — | Reputeinfosystems Armember | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28. | |
| Modificada | Media (6.1) | 0.68% | — | Butlerblog Wp-members | 9/4/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.50% | — | Caseproof Memberpress | 9/4/2024 | 17/6/2026 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.3) | 0.56% | — | S2memberAI | 9/4/2024 | 17/6/2026 | The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of… | |
| Modificada | Media (4.3) | 0.90% | 💥 PoC | Strangerstudios Paid Memberships PRO | 9/4/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible… | |
| Aplazada | Media (5.3) | 0.44% | — | Paidmembershipspro Mailchimp ADD ONAI | 31/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This issue affects Paid Memberships Pro – Mailchimp Add On: from n/a through 2.3.4. | |
| Aplazada | Media (5.3) | 0.47% | — | Paidmembershipspro Payfast Gateway ADD ONAI | 29/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1. | |
| Modificada | Crítica (9.8) | 0.65% | — | Reputeinfosystems Armember | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. | |
| Modificada | Alta (8.8) | 0.61% | — | Reputeinfosystems Armember | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. | |
| Modificada | Alta (8.8) | 0.61% | — | Wpeverest User Registration & Membership | 26/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. | |
| Modificada | Media (5.4) | 0.33% | — | Reputeinfosystems Armember | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup allows Stored XSS.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels,… | |
| Analizada | Media (6.1) | 0.44% | — | Wpdarko Team Members | 18/3/2024 | 17/6/2026 | The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.23% | — | Cozmoslabs Paid Membership Subscriptions | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.10.4. | |
| Modificada | Media (6.1) | 0.87% | — | Simple-membership-plugin Simple Membership | 13/3/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Crítica (9.8) | 89% | 💥 Exploit | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Modificada | Media (6.1) | 27% | — | Ultimatemember Ultimate Member | 13/3/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This… |