Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Wishlistmember Wishlist Member XAI | 19/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Tips AND Tricks HQ WP EmemberAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2. | |
| Aplazada | Media (5.3) | 0.31% | — | Tips AND Tricks HQ WP EmemberAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2. | |
| Aplazada | Alta (8.1) | 0.36% | — | Membershipupplugin Membership Plugin Restrict ContentAI | 5/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active… | |
| Aplazada | Media (6.5) | 0.26% | — | Butlerblog Wp-membersAI | 4/3/2026 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Crítica (9.8) | 28% | 💥 Exploit | User Registration MembershipAI | 3/3/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role… | |
| Aplazada | Media (5.3) | 0.19% | — | User Registration AND MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes… | |
| Aplazada | Alta (8.1) | 0.36% | — | User Registration MembershipAI | 26/2/2026 | 17/6/2026 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has… | |
| Aplazada | Media (6.5) | 0.36% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8. | |
| Aplazada | Media (6.5) | 0.24% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by… | |
| Aplazada | Media (4.3) | 0.19% | — | Simple-membership-plugin Simple MembershipAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9. | |
| Aplazada | Crítica (9.8) | 0.38% | — | S2memberAI | 19/2/2026 | 17/6/2026 | The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary… | |
| Aplazada | Media (6.4) | 0.32% | — | S2memberAI | 19/2/2026 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escaping.… | |
| Modificada | Crítica (9.8) | 0.67% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | |
| Modificada | Alta (7.5) | 0.45% | — | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | |
| Modificada | Crítica (9.8) | 0.40% | 💥 PoC | Codeastro Membership Management System | 18/2/2026 | 8/9/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | |
| Aplazada | Media (6.1) | 0.22% | — | Ultimatemember Ultimate MemberAI | 18/2/2026 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input… | |
| Aplazada | Media (4.4) | 0.33% | — | Membership PluginAI | 18/2/2026 | 17/6/2026 | The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice settings fields in all versions up to, and including, 3.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.3) | 0.29% | — | Wclovers Wcfm MembershipAI | 10/2/2026 | 17/6/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it… | |
| Analizada | Media (5.1) | 0.17% | — | Samsung Members | 4/2/2026 | 17/6/2026 | Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members. | |
| Analizada | Alta (7) | 0.32% | — | Samsung Members | 4/2/2026 | 17/6/2026 | Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (5.4) | 0.11% | — | Simple-membership-plugin Simple Membership WP User ImportAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1. | |
| Aplazada | Alta (8.8) | 0.32% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.1) | 0.26% | — | Expresstechsoftware Memberpress Discord AddonAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.4. |