Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.34%—Profilegrid Memberships AND User Profiles FOR WoocommerceAI9/7/20269/7/2026
The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()…
AplazadaAlta (8.1)0.40%—Wclovers Wcfm MembershipAI8/7/20268/7/2026
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it…
AplazadaAlta (8.8)0.51%—Simple-membership-plugin Simple MembershipAI6/7/20266/7/2026
The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in…
AplazadaMedia (6.5)0.27%—User Registration MembershipAI2/7/20262/7/2026
The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying…
AplazadaAlta (8.1)0.38%—Paid Membership PluginAI27/6/202629/6/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active…
AplazadaAlta (8.8)0.20%—Paidmembershipspro Paid Memberships PROAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
AplazadaMedia (6.5)0.30%—User Registration AND MembershipAI26/6/202626/6/2026
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and…
AplazadaMedia (5.3)0.35%—Simple-membership-plugin Simple MembershipAI18/6/202618/6/2026
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by…
AplazadaMedia (6.5)0.22%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
AplazadaAlta (7.5)0.35%—Simple-membership-plugin Simple MembershipAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
AplazadaAlta (7.3)0.30%—Wclovers Wcfm MembershipAI27/5/202617/6/2026
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.
AplazadaAlta (8.8)0.28%—Supsystic MembershipAI16/5/202629/9/2026
Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payloads to extract sensitive database…
AplazadaMedia (5.3)0.43%💥 PoCUser Registration MembershipAI14/5/202617/6/2026
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or…
AplazadaMedia (6.5)0.43%—Codeastro Membership Management SystemAI7/5/20265/7/2026
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.
AplazadaMedia (4.3)0.35%—User Registration MembershipAI5/5/202617/6/2026
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AplazadaAlta (7.1)0.37%—Paidmembershipspro Paid Memberships PROAI2/5/202617/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and…
AplazadaMedia (6.1)0.56%💥 ExploitUser Registration MembershipAI13/4/202617/6/2026
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed…
AplazadaMedia (6.5)0.31%—User Registration MembershipAI8/4/202624/7/2026
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on…
AplazadaMedia (5.5)0.41%—Code-projects Student Membership SystemAI31/3/202624/7/2026
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The exploit has…
AplazadaBaja (2.1)0.32%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)0.32%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
AplazadaMedia (6.9)0.41%—Code-projects Student Membership SystemAI31/3/202617/6/2026
A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the component User Registration Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely.
AplazadaBaja (2)2.1%—Code-projects Chamber OF Commerce Membership Management SystemAI29/3/202617/6/2026
A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection. The attack may be initiated remotely. The exploit is publicly…
AplazadaAlta (8.1)0.34%—Wpindeed Ultimate Membership PROAI25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7.
AplazadaMedia (5.4)0.30%—User Registration MembershipAI24/3/202617/6/2026
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead…
Orbitaley — Vulnerabilidades