Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | User Registration MembershipAI | 24/3/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead… | |
| Aplazada | Media (4.3) | 0.34% | — | Restrictcontent Membership Plugin Restrict ContentAI | 20/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users… | |
| Aplazada | Alta (8.1) | 0.36% | — | Membershipupplugin Membership Plugin Restrict ContentAI | 5/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active… | |
| Aplazada | Crítica (9.8) | 28% | 💥 Exploit | User Registration MembershipAI | 3/3/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role… | |
| Aplazada | Media (5.3) | 0.19% | — | User Registration AND MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes… | |
| Aplazada | Alta (8.1) | 0.36% | — | User Registration MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has… | |
| Aplazada | Media (6.5) | 0.24% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by… | |
| Aplazada | Media (4.3) | 0.19% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9. | |
| Modificada | Crítica (9.8) | 0.66% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | |
| Modificada | Alta (7.5) | 0.43% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | |
| Modificada | Crítica (9.8) | 0.39% | 💥 PoC | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | |
| Aplazada | Media (4.4) | 0.32% | — | Membership PluginAI | 18/2/2026 | 17/6/2026 | The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice settings fields in all versions up to, and including, 3.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.3) | 0.27% | — | Wclovers Wcfm MembershipAI | 10/2/2026 | 17/6/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Media (5.4) | 0.11% | — | Simple-membership-plugin Simple Membership WP User ImportAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1. | |
| Aplazada | Alta (8.8) | 0.32% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4. | |
| Analizada | Baja (2) | 0.35% | — | Carmelo Intern Membership Management System | 11/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.4) | 0.15% | — | User Registration MembershipAI | 10/1/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the… | |
| Analizada | Baja (2) | 0.38% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may… | |
| Analizada | Baja (2) | 0.42% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /intern/admin/delete_admin.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Baja (2) | 0.37% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Media (5.5) | 0.44% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Analizada | Baja (2) | 0.36% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Baja (2) | 0.40% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/edit_students.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (2) | 0.36% | — | Carmelo Intern Membership Management System | 8/1/2026 | 17/6/2026 | A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin/edit_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |