Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Ultimatemember ForumwpAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4. | |
| Analizada | Baja (1.9) | 0.22% | — | Fabian Chamber OF Commerce Membership Management System | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /membership_profile.php of the component Your Info Handler. Performing manipulation of the argument Full Name/Address/City/State results in cross site scripting. The attack is… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attackers to reset arbitrary… | |
| Aplazada | Media (5.3) | 0.27% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to create arbitrary membership tags and modify CRM… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Tiare MembershipAI | 27/11/2025 | 17/6/2026 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Crítica (9.8) | 0.46% | — | Findall MembershipAI | 27/11/2025 | 17/6/2026 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user' and the… | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.3) | 0.24% | — | Ultimate Member Widgets FOR ElementorAI | 20/11/2025 | 17/6/2026 | The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial… | |
| Aplazada | Media (4.4) | 0.23% | — | MembershipworksAI | 12/11/2025 | 17/6/2026 | The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (7.1) | 0.17% | — | Dazzlersoft Team Members ShowcaseAI | 12/11/2025 | 17/6/2026 | The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins. | |
| Aplazada | Crítica (9.8) | 0.50% | — | S2member Project S2memberAI | 6/11/2025 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701. | |
| Analizada | Alta (8.1) | 0.57% | — | Samsung Members | 5/11/2025 | 17/6/2026 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (5.3) | 0.23% | — | Cozmoslabs Paid Membership SubscriptionsAI | 5/11/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and… | |
| Aplazada | Media (4.4) | 0.19% | — | ClubmemberAI | 4/11/2025 | 17/6/2026 | The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (8.8) | 0.56% | — | Wpcom MemberAI | 1/11/2025 | 17/6/2026 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the… | |
| Aplazada | Alta (7.1) | 0.14% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.8.0. | |
| Aplazada | Crítica (9) | 0.42% | 💥 PoC | Cristian Lavaque S2memberAI | 22/10/2025 | 29/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905. | |
| Aplazada | Media (6.5) | 0.27% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Strangerstudios Memberlite ShortcodesAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Yourmembership YM SSO LoginAI | 15/10/2025 | 17/6/2026 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to read the profile data… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpdarko Team MembersAI | 27/9/2025 | 17/6/2026 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Baja (2.1) | 0.38% | — | Campcodes Society Membership Information System | 23/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be… | |
| Aplazada | Media (5.3) | 0.27% | — | Memberful-wpAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in memberful Memberful - Membership Plugin memberful-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberful - Membership Plugin: from n/a through <= 1.75.0. |