Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

373 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.5)0.37%—Simple-membership-plugin Simple MembershipAI3/10/20263/10/2026
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on…
AplazadaCrítica (9.8)0.33%—Divi MembershipAI2/10/20263/10/2026
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash…
AplazadaCrítica (9.8)0.40%—Divi MembershipAI2/10/20263/10/2026
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership…
AplazadaMedia (5.3)0.21%—Wpdarko Team MembersAI26/9/202629/9/2026
The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the…
AplazadaMedia (5.3)0.21%—Cozmoslabs Paid Membership SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.
AplazadaBaja (3.7)0.15%—Paidmembershipssubscriptions Paid Memberships SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
AplazadaMedia (5.3)0.29%—Simple-membership-plugin Simple MembershipAI17/9/202617/9/2026
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
AplazadaMedia (5.3)0.30%—Paidmembershipsincorporated Paid Memberships SubscriptionsAI17/9/202618/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
AplazadaMedia (5.4)0.23%—Simple-membership-plugin Simple MembershipAI13/9/202614/9/2026
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
AplazadaBaja (3.7)0.28%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile…
AplazadaAlta (7.5)0.32%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan…
AplazadaMedia (4.7)0.29%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.
AplazadaAlta (7.2)0.46%—User Registration MembershipAI13/9/202614/9/2026
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to…
AplazadaMedia (6.1)0.37%—WP MembersAI11/9/202611/9/2026
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaBaja (2.1)0.33%—Itsourcecode Information System Society Membership SystemAI7/9/202628/9/2026
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit…
AplazadaMedia (5.3)0.29%—Wclovers Wcfm MembershipAI4/9/20264/9/2026
Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.
AplazadaAlta (7.1)0.28%—Wclovers Wcfm MembershipAI3/9/20267/9/2026
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
AplazadaMedia (5.4)0.14%—Simple Membership Mailchimp IntegrationAI2/9/20263/9/2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is…
AplazadaMedia (5.3)0.58%—Simple-membership-plugin Simple MembershipAI1/9/20261/9/2026
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple…
AplazadaAlta (7.2)0.46%—User Registration AND MembershipAI28/8/202628/8/2026
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change…
AplazadaMedia (4.3)0.25%—User Registration MembershipAI28/8/202628/8/2026
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an…
AplazadaCrítica (9.8)0.61%—User Registration Membership PROAI20/8/202620/8/2026
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
AplazadaAlta (8.5)0.36%—Yith Woocommerce Membership PremiumAI19/8/202620/8/2026
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
AplazadaMedia (5.3)0.32%—Wpswings Membership FOR WoocommerceAI19/8/202626/8/2026
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the…
AplazadaMedia (5.3)0.16%—Simple-membership-plugin Simple MembershipAI6/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they…