Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.53% | — | Wpswings Membership FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0. | |
| Aplazada | Crítica (9.1) | 0.45% | — | User Registration MembershipAI | 13/7/2026 | 13/7/2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment. | |
| Aplazada | Alta (8.1) | 0.35% | — | User Registration Membership User Registration AND MembershipAI | 13/7/2026 | 13/7/2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress… | |
| Aplazada | Media (5.3) | 0.47% | — | Samsung MembersAI | 11/7/2026 | 14/7/2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count… | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Alta (8.1) | 0.40% | — | Wclovers Wcfm MembershipAI | 8/7/2026 | 8/7/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it… | |
| Aplazada | Alta (8.8) | 0.51% | — | Simple-membership-plugin Simple MembershipAI | 6/7/2026 | 6/7/2026 | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in… | |
| Aplazada | Media (6.5) | 0.27% | — | User Registration MembershipAI | 2/7/2026 | 2/7/2026 | The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying… | |
| Aplazada | Media (4.4) | 0.34% | — | Team Members Multi Language Supported Team PluginAI | 30/6/2026 | 30/6/2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (8.1) | 0.38% | — | Paid Membership PluginAI | 27/6/2026 | 29/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active… | |
| Aplazada | Alta (8.8) | 0.20% | — | Paidmembershipspro Paid Memberships PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | User Registration AND MembershipAI | 26/6/2026 | 26/6/2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and… | |
| Aplazada | Media (5.3) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 18/6/2026 | 18/6/2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by… | |
| Aplazada | Media (6.5) | 0.22% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. | |
| Analizada | Media (6.9) | 0.10% | — | Samsung Members | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. | |
| Aplazada | Alta (7.3) | 0.30% | — | Wclovers Wcfm MembershipAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10. | |
| Aplazada | Alta (8.8) | 0.28% | — | Supsystic MembershipAI | 16/5/2026 | 29/9/2026 | Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payloads to extract sensitive database… | |
| Aplazada | Media (5.3) | 0.43% | 💥 PoC | User Registration MembershipAI | 14/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or… | |
| Aplazada | Media (6.5) | 0.43% | — | Codeastro Membership Management SystemAI | 7/5/2026 | 5/7/2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. | |
| Aplazada | Media (4.3) | 0.35% | — | User Registration MembershipAI | 5/5/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.37% | — | Paidmembershipspro Paid Memberships PROAI | 2/5/2026 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and… | |
| Aplazada | Media (6.1) | 0.56% | 💥 Exploit | User Registration MembershipAI | 13/4/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed… | |
| Aplazada | Alta (8.8) | 1.1% | — | Advanced Members FOR ACFAI | 8/4/2026 | 24/7/2026 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (6.5) | 0.31% | — | User Registration MembershipAI | 8/4/2026 | 24/7/2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on… |