Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.33% | — | Samsung Members | 7/5/2025 | 17/6/2026 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members. | |
| Aplazada | Media (5.3) | 0.42% | — | User Registration MembershipAI | 6/5/2025 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key.… | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdarko Team MembersAI | 1/5/2025 | 17/6/2026 | The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social Link icons in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (6.9) | 0.56% | — | Codeastro Membership Management System | 28/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.29% | — | Wpeverest User Registration & Membership | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0. | |
| Analizada | Alta (8.1) | 9.5% | 💥 Exploit | Wpeverest User Registration & Membership | 22/4/2025 | 17/6/2026 | The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Urbango MembershipAI | 19/4/2025 | 17/6/2026 | The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_register_role' field. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows DOM-Based XSS.This issue affects Membership For WooCommerce: from n/a through <= 2.8.0. | |
| Analizada | Alta (8.1) | 49% | 💥 Exploit | Wpeverest User Registration & Membership | 14/4/2025 | 17/6/2026 | The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges | |
| Analizada | Media (4.3) | 0.31% | — | Wpeverest User Registration & Membership | 12/4/2025 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing validation on the 'user_id' user controlled… | |
| Analizada | Media (5.3) | 0.28% | — | Wpeverest User Registration & Membership | 12/4/2025 | 17/6/2026 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user… | |
| Aplazada | Media (6.5) | 0.36% | — | Membersonly Buddypress Members OnlyAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas BuddyPress Members Only buddypress-members-only allows Stored XSS.This issue affects BuddyPress Members Only: from n/a through <= 3.5.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Sultan Nasir Uddin Team Members FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder team-members-for-elementor allows Stored XSS.This issue affects Team Members for Elementor Page Builder: from n/a through <= 1.0.4. | |
| Aplazada | Media (4.3) | 0.37% | — | Wpbean OUR Team MembersAI | 1/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPBean Our Team Members our-team-members.This issue affects Our Team Members: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.22% | — | MemberspaceAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in memberspace MemberSpace memberspace allows Reflected XSS.This issue affects MemberSpace: from n/a through <= 2.1.13. | |
| Modificada | Media (4.8) | 0.31% | — | Wpeverest User Registration & Membership | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Stored XSS.This issue affects User Registration: from n/a through <= 4.0.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Naren Members Page Only FOR Logged IN UsersAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XSS.This issue affects Members page only for logged in users: from n/a through <= 1.4.2. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Academist MembershipAI | 1/3/2025 | 17/6/2026 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Alloggio MembershipAI | 1/3/2025 | 17/6/2026 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity through the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Setsail MembershipAI | 1/3/2025 | 17/6/2026 | The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access… | |
| Aplazada | Media (4.3) | 0.29% | — | Subscriptions Memberships FOR PaypalAI | 26/2/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged… | |
| Aplazada | Media (5.3) | 0.55% | — | SuremembersAI | 26/2/2025 | 17/6/2026 | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content. | |
| Analizada | Media (4.6) | 0.22% | — | Samsung Members | 4/2/2025 | 17/6/2026 | Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles. | |
| Aplazada | Alta (7.1) | 0.32% | — | Wp.insider Simple Membership Custom MessagesAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership Custom Messages simple-membership-custom-messages allows Reflected XSS.This issue affects Simple Membership Custom Messages: from n/a through <= 2.4. | |
| Aplazada | Alta (7.1) | 0.39% | — | Explara MembershipAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Membership explara-membership allows Reflected XSS.This issue affects Explara Membership: from n/a through <= 0.0.7. |