Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.5) | 0.37% | — | Simple-membership-plugin Simple MembershipAI | 3/10/2026 | 3/10/2026 | The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on… | |
| Recibida | Alta (7.2) | 0.25% | — | Ultimatemember Ultimate MemberAI | 3/10/2026 | 3/10/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This… | |
| Recibida | Alta (7.5) | 0.40% | — | Ultimatemember Ultimate MemberAI | 3/10/2026 | 3/10/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action.… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Divi MembershipAI | 2/10/2026 | 2/10/2026 | The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Divi MembershipAI | 2/10/2026 | 2/10/2026 | The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership… | |
| Aplazada | Alta (7.6) | 0.28% | — | Ultimatemember Ultimate MemberAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1. | |
| Aplazada | Alta (8) | 0.12% | — | MemberfulAI | 1/10/2026 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0. | |
| Aplazada | Media (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Wpdarko Team MembersAI | 26/9/2026 | 29/9/2026 | The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the… | |
| Aplazada | Alta (8.8) | 1.0% | — | S2memberAI | 25/9/2026 | 25/9/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name… | |
| Aplazada | Media (5.3) | 0.21% | — | Cozmoslabs Paid Membership SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | |
| Aplazada | Baja (3.7) | 0.15% | — | Paidmembershipssubscriptions Paid Memberships SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | |
| Aplazada | Baja (3.7) | 0.25% | — | TO DO List MemberAI | 21/9/2026 | 21/9/2026 | The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site. | |
| Aplazada | Alta (8.8) | 0.51% | — | Ultimatemember Ultimate MemberAI | 19/9/2026 | 21/9/2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that… | |
| Aplazada | Media (5.3) | 0.29% | — | Simple-membership-plugin Simple MembershipAI | 17/9/2026 | 17/9/2026 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | |
| Aplazada | Alta (8.8) | 0.51% | — | TO DO List MemberAI | 17/9/2026 | 18/9/2026 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active… | |
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAIErik Hjortsberg EmberAI | 15/9/2026 | 17/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent CONTINUATION fragments without a size bound. A remote peer can keep an incomplete block open and exhaust… | |
| Aplazada | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAIHttp4s-ember-serverAITypelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket… | |
| Aplazada | Media (5.4) | 0.23% | — | Simple-membership-plugin Simple MembershipAI | 13/9/2026 | 14/9/2026 | The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level. | |
| Aplazada | Baja (3.7) | 0.28% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile… | |
| Aplazada | Alta (7.5) | 0.32% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan… | |
| Aplazada | Media (4.7) | 0.29% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing. | |
| Aplazada | Alta (7.2) | 0.46% | — | User Registration MembershipAI | 13/9/2026 | 14/9/2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to… | |
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… |