Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.28%—Codeastro Membership Management System2/9/202417/6/2026
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.
ModificadaCrítica (10)0.54%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
ModificadaCrítica (9.8)0.55%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaAlta (7.1)0.27%—Wpindeed Ultimate Membership PROAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaMedia (6.1)0.49%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (4.3)0.59%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view…
AnalizadaAlta (8.8)0.33%—Lopalopa Live Membership System12/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
AnalizadaAlta (7.6)1.1%—Lopalopa Live Membership System12/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.
AnalizadaCrítica (9.8)1.0%—Lopalopa Live Membership System12/8/202417/6/2026
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
AnalizadaCrítica (9.8)1.2%—Lopalopa Live Membership System12/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
ModificadaMedia (6.5)0.52%—Strangerstudios Paid Memberships PRO30/7/202417/6/2026
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
AnalizadaMedia (4.9)0.56%—Strangerstudios Paid Memberships PRO30/7/202417/6/2026
The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.
AplazadaMedia (6.5)0.34%—Wpdarko Team MembersAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3.
ModificadaAlta (7.2)0.74%—Strangerstudios Paid Memberships PRO9/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
AnalizadaAlta (8.8)0.48%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
AplazadaAlta (8.2)0.44%—Paidmembershipspro Ccbill GatewayAI19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.
ModificadaMedia (5.4)0.22%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated…
ModificadaMedia (5.3)0.44%—Membersonly Buddypress Members Only6/6/202417/6/2026
The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All Other Sections On Your Site Will be Opened to Guest" feature (when unset) and…
AnalizadaCrítica (9.8)0.77%—Simple-membership-plugin Simple Membership17/5/202417/6/2026
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
AnalizadaAlta (8.8)0.91%—Simple-membership-plugin Simple Membership17/5/202417/6/2026
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
ModificadaMedia (5.4)0.43%—Simple-membership-plugin Simple Membership14/5/202417/6/2026
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (4.3)0.30%—Strangerstudios Paid Memberships PRO2/5/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it…
AplazadaMedia (5.3)0.50%—Butlerblog Wp-membersAI26/4/202417/6/2026
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to…
ModificadaMedia (5.4)0.34%—Simple-membership-plugin Simple Membership25/4/202417/6/2026
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaAlta (8.8)0.24%—Strangerstudios Paid Memberships PRO24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
Orbitaley — Vulnerabilidades