Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan… | |
| Aplazada | Media (4.7) | 0.29% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing. | |
| Aplazada | Alta (7.2) | 0.46% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to… | |
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… | |
| Aplazada | Media (6.1) | 0.37% | — | WP MembersAI | 11/9/2026 | 11/9/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Information System Society Membership SystemAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Crítica (9.8) | 0.30% | — | MemberdashAI | 6/9/2026 | 8/9/2026 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including… | |
| Aplazada | Media (5.3) | 0.29% | — | Wclovers Wcfm MembershipAI | 4/9/2026 | 4/9/2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wclovers Wcfm MembershipAI | 3/9/2026 | 7/9/2026 | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Membership Mailchimp IntegrationAI | 2/9/2026 | 3/9/2026 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is… | |
| Aplazada | Media (5.3) | 0.23% | — | Ultimatemember Ultimate MemberAI | 2/9/2026 | 3/9/2026 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation. | |
| Aplazada | Media (5.3) | 0.58% | — | Simple-membership-plugin Simple MembershipAI | 1/9/2026 | 1/9/2026 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple… | |
| Aplazada | Crítica (9.8) | 0.34% | — | MemberheroAI | 29/8/2026 | 3/9/2026 | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving… | |
| Aplazada | Alta (7.2) | 0.46% | — | User Registration AND MembershipAI | 28/8/2026 | 28/8/2026 | The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change… | |
| Aplazada | Media (4.3) | 0.25% | — | User Registration MembershipAI | 28/8/2026 | 28/8/2026 | The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an… | |
| Aplazada | Alta (8.1) | 0.23% | — | Ultimatemember Ultimate MemberAI | 28/8/2026 | 28/8/2026 | The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register… | |
| Aplazada | Media (6.4) | 0.28% | — | Ultimatemember Ultimate MemberAI | 25/8/2026 | 28/9/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up to, and including, 2.12.1 due to… | |
| Aplazada | Crítica (9.8) | 0.61% | — | User Registration Membership PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Yith Woocommerce Membership PremiumAI | 19/8/2026 | 20/8/2026 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 19/8/2026 | 26/8/2026 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Wishlistmember Wishlist MemberAI | 14/8/2026 | 14/8/2026 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and… | |
| Aplazada | Media (6.8) | 0.43% | — | S2memberAI | 10/8/2026 | 26/8/2026 | The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS). | |
| Aplazada | Media (5.3) | 0.16% | — | Simple-membership-plugin Simple MembershipAI | 6/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they… | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | |
| Aplazada | Media (4.3) | 0.14% | — | Realhomes MembershipsAI | 6/8/2026 | 26/8/2026 | The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying. |