Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.14%—Realhomes MembershipsAI6/8/202626/8/2026
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
AplazadaMedia (6.1)0.26%—Ember Dynamic Render TemplateAIEmber Template CompilationAI5/8/202626/8/2026
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input.
AplazadaAlta (7.5)0.41%—User Registration MembershipAI5/8/202626/8/2026
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
AplazadaCrítica (9.3)0.51%—Kadence MembershipsAI5/8/202612/8/2026
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the…
AplazadaMedia (5.4)0.29%—Cozmoslabs Paid Membership SubscriptionsAI4/8/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its…
AplazadaMedia (6.1)0.27%—Simple-membership-plugin Simple MembershipAI3/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's…
AplazadaCrítica (9.4)0.42%—Simple-membership-plugin Simple MembershipAI3/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over…
AplazadaMedia (4.3)0.40%—Realhomes MembershipsAI1/8/202612/8/2026
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaBaja (3.7)0.28%—Cozmoslabs Paid Membership SubscriptionsAI31/7/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
AplazadaMedia (4.3)0.27%—Cozmoslabs Paid Membership SubscriptionsAI31/7/202626/8/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier.
AplazadaAlta (8.1)0.38%—Ultimatemember Ultimate MemberAI31/7/202626/8/2026
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role…
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
AplazadaCrítica (9.8)0.47%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
AplazadaCrítica (9.8)0.32%—Code RO Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeatro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20261/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
AplazadaCrítica (9.8)0.32%—Codeastro Membership Management SystemAI30/7/20265/10/2026
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
AplazadaMedia (5.3)0.40%—Klubraum Membership RequestAI29/7/202630/7/2026
The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the plugin's settings, including…
AplazadaMedia (6.4)0.26%—Strangerstudios Paid Memberships PROAI28/7/202628/7/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output…
AplazadaAlta (7.5)0.35%—Paid Member SubscriptionsAI27/7/202627/7/2026
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
AplazadaCrítica (9.8)2.1%💥 ExploitMemberglutAI27/7/202627/7/2026
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
AplazadaAlta (7.5)0.39%—Paidmembershipspro Paid Memberships PROAI24/7/202624/7/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the…
AplazadaMedia (6.5)0.22%—Wishlistmember Wishlist Member XAI23/7/202623/7/2026
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
Orbitaley — Vulnerabilidades