Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Wpswings Membership FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Membership For WooCommerce: from n/a through <= 3.0.3. | |
| Aplazada | Media (6.4) | 0.24% | — | Membership Plugin Restrict ContentAI | 23/12/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Elated MembershipAI | 10/12/2025 | 17/6/2026 | The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'eltdf_membership_check_facebook_user' and the… | |
| Analizada | Baja (1.9) | 0.22% | — | Fabian Chamber OF Commerce Membership Management System | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /membership_profile.php of the component Your Info Handler. Performing manipulation of the argument Full Name/Address/City/State results in cross site scripting. The attack is… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attackers to reset arbitrary… | |
| Aplazada | Media (5.3) | 0.27% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to create arbitrary membership tags and modify CRM… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Tiare MembershipAI | 27/11/2025 | 17/6/2026 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Findall MembershipAI | 27/11/2025 | 17/6/2026 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user' and the… | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Aplazada | Media (4.4) | 0.23% | — | MembershipworksAI | 12/11/2025 | 17/6/2026 | The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (5.3) | 0.23% | — | Cozmoslabs Paid Membership SubscriptionsAI | 5/11/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and… | |
| Aplazada | Alta (7.1) | 0.14% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.8.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Media (5.3) | 0.30% | — | Yourmembership YM SSO LoginAI | 15/10/2025 | 17/6/2026 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to read the profile data… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Society Membership Information System | 23/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be… | |
| Aplazada | Media (4.9) | 0.34% | — | User Registration MembershipAI | 6/9/2025 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.9) | 0.18% | — | Gourl Bitcoin Payment Gateway Paid Downloads MembershipAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership allows Stored XSS.This issue affects GoUrl Bitcoin Payment Gateway & Paid Downloads &… | |
| Aplazada | Alta (8.1) | 0.65% | — | Wptobe MembershipsAI | 23/8/2025 | 17/6/2026 | The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (5.4) | 0.22% | — | E-plugins WP MembershipAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.5) | 0.36% | — | Wpswings Membership FOR WoocommerceAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.9.0. | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Carmelo Intern Membership Management System | 2/8/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… |