Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.61%—User Registration Membership PROAI20/8/202620/8/2026
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
AplazadaAlta (7.5)0.39%—Paidmembershipspro Paid Memberships PROAI24/7/202624/7/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the…
AplazadaCrítica (9.1)0.45%—Joomdonation Membership PROAI21/7/202623/7/2026
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
AplazadaAlta (8.8)0.20%—Paidmembershipspro Paid Memberships PROAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
AplazadaAlta (7.1)0.37%—Paidmembershipspro Paid Memberships PROAI2/5/202617/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and…
AplazadaAlta (8.1)0.34%—Wpindeed Ultimate Membership PROAI25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7.
AplazadaMedia (6.3)0.35%—Indeed Membership PROAI16/10/202417/6/2026
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying…
AplazadaCrítica (9.8)0.69%—Wpindeed Ultimate Membership PROAI16/10/202417/6/2026
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
ModificadaCrítica (10)0.54%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
ModificadaCrítica (9.8)0.55%—Wpindeed Ultimate Membership PRO19/8/202417/6/2026
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaAlta (7.1)0.27%—Wpindeed Ultimate Membership PROAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
AplazadaAlta (8.2)0.44%—Paidmembershipspro Ccbill GatewayAI19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.
AplazadaMedia (5.3)0.44%—Paidmembershipspro Mailchimp ADD ONAI31/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This issue affects Paid Memberships Pro – Mailchimp Add On: from n/a through 2.3.4.
AplazadaMedia (5.3)0.47%—Paidmembershipspro Payfast Gateway ADD ONAI29/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.
ModificadaMedia (5.4)0.55%—Paidmembershipspro Custom User Profile Fields FOR User Registration30/1/202317/6/2026
The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against…