Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.56% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 14/1/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the… | |
| Analizada | Media (5.3) | 0.48% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 18/12/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Biagiotti MembershipAI | 18/12/2024 | 17/6/2026 | The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, such as… | |
| Aplazada | Media (6.5) | 0.60% | — | Miniorange Yourmembership Single Sign ONAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange YourMembership Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YourMembership Single Sign On: from n/a through 1.1.3. | |
| Aplazada | Media (5.3) | 0.38% | — | Samsung MembersAI | 11/12/2024 | 17/6/2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted… | |
| Analizada | Alta (7.5) | 0.63% | — | Simple-membership-plugin Simple Membership | 21/11/2024 | 17/6/2026 | The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as… | |
| Aplazada | Alta (7.1) | 0.27% | — | Ristretto Apps Dashing MembershipsAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ristretto Apps Dashing Memberships dashing-memberships allows Reflected XSS.This issue affects Dashing Memberships: from n/a through <= 1.1. | |
| Analizada | Alta (7.3) | 0.46% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 9/11/2024 | 17/6/2026 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a… | |
| Aplazada | Alta (7.1) | 0.27% | — | Biplob018 Team Showcase AND Slider Team Members BuilderAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biplob018 Team Showcase and Slider – Team Members Builder team-showcase-ultimate allows Reflected XSS.This issue affects Team Showcase and Slider – Team Members Builder: from n/a through <= 1.3. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wpmembership WP MembershipAI | 9/11/2024 | 17/6/2026 | The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Analizada | Crítica (9.8) | 0.67% | — | Strangerstudios Paid Memberships PRO | 1/11/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | |
| Analizada | Media (5.4) | 0.45% | — | Butlerblog Wp-members | 25/10/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.27% | — | Simple-membership-plugin Simple Membership | 24/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affects Simple Membership: from n/a through <= 4.5.3. | |
| Analizada | Media (6.1) | 0.47% | — | Butlerblog Wp-members | 22/10/2024 | 17/6/2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.4) | 0.32% | — | Codeastro Membership Management System | 21/10/2024 | 17/6/2026 | CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php | |
| Analizada | Media (5.4) | 0.30% | — | Codeastro Membership Management System | 21/10/2024 | 17/6/2026 | CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php. | |
| Modificada | Alta (8.8) | 0.42% | — | Themexpo Rs-members | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.8) | 0.50% | — | Taketin TO WP MembershipAI | 16/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17. | |
| Aplazada | Media (6.3) | 0.35% | — | Indeed Membership PROAI | 16/10/2024 | 17/6/2026 | The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Wpindeed Ultimate Membership PROAI | 16/10/2024 | 17/6/2026 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
| Aplazada | Media (4.7) | 0.33% | — | Wp.insider Simple Membership After Login RedirectionAI | 10/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a through <= 1.6. | |
| Analizada | Media (6.1) | 0.39% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 2/10/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for… | |
| Analizada | Alta (8.6) | 0.44% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. | |
| Analizada | Alta (7.5) | 0.50% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information. | |
| Analizada | Media (6.1) | 0.35% | — | Codeastro Membership Management System | 27/9/2024 | 17/6/2026 | Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component. |