Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.61% | — | User Registration Membership PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Paidmembershipspro Paid Memberships PROAI | 24/7/2026 | 24/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Joomdonation Membership PROAI | 21/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | |
| Aplazada | Alta (8.8) | 0.20% | — | Paidmembershipspro Paid Memberships PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.37% | — | Paidmembershipspro Paid Memberships PROAI | 2/5/2026 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and… | |
| Aplazada | Alta (8.1) | 0.34% | — | Wpindeed Ultimate Membership PROAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7. | |
| Aplazada | Media (6.3) | 0.35% | — | Indeed Membership PROAI | 16/10/2024 | 17/6/2026 | The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Wpindeed Ultimate Membership PROAI | 16/10/2024 | 17/6/2026 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
| Modificada | Crítica (10) | 0.54% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Crítica (9.8) | 0.55% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpindeed Ultimate Membership PROAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (8.2) | 0.44% | — | Paidmembershipspro Ccbill GatewayAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3. | |
| Aplazada | Media (5.3) | 0.44% | — | Paidmembershipspro Mailchimp ADD ONAI | 31/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This issue affects Paid Memberships Pro – Mailchimp Add On: from n/a through 2.3.4. | |
| Aplazada | Media (5.3) | 0.47% | — | Paidmembershipspro Payfast Gateway ADD ONAI | 29/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1. | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… |