Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.15% | — | Paidmembershipssubscriptions Paid Memberships SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | |
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Media (4.3) | 0.14% | — | Realhomes MembershipsAI | 6/8/2026 | 26/8/2026 | The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Kadence MembershipsAI | 5/8/2026 | 12/8/2026 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the… | |
| Aplazada | Media (4.3) | 0.40% | — | Realhomes MembershipsAI | 1/8/2026 | 12/8/2026 | The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.26% | — | Strangerstudios Paid Memberships PROAI | 28/7/2026 | 28/7/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output… | |
| Aplazada | Alta (7.5) | 0.39% | — | Paidmembershipspro Paid Memberships PROAI | 24/7/2026 | 24/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the… | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Alta (8.8) | 0.20% | — | Paidmembershipspro Paid Memberships PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.37% | — | Paidmembershipspro Paid Memberships PROAI | 2/5/2026 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attackers to reset arbitrary… | |
| Aplazada | Media (5.3) | 0.27% | — | Ntzapps CRM MembershipsAI | 5/12/2025 | 25/9/2026 | The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for unauthenticated attackers to create arbitrary membership tags and modify CRM… | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.1) | 0.14% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.8.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (8.1) | 0.65% | — | Wptobe MembershipsAI | 23/8/2025 | 17/6/2026 | The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (4.3) | 0.29% | — | Subscriptions Memberships FOR PaypalAI | 26/2/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged… | |
| Aplazada | Alta (7.1) | 0.27% | — | Ristretto Apps Dashing MembershipsAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ristretto Apps Dashing Memberships dashing-memberships allows Reflected XSS.This issue affects Dashing Memberships: from n/a through <= 1.1. | |
| Analizada | Crítica (9.8) | 0.67% | — | Strangerstudios Paid Memberships PRO | 1/11/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | |
| Modificada | Media (6.5) | 0.52% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. | |
| Analizada | Media (4.9) | 0.56% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |
| Modificada | Alta (7.2) | 0.74% | — | Strangerstudios Paid Memberships PRO | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. | |
| Analizada | Alta (8.8) | 0.48% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. |