Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.28% | — | Paid Member SubscriptionsAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | |
| Aplazada | Media (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Paid Member SubscriptionsAI | 27/7/2026 | 27/7/2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Paid Member SubscriptionsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paid Member SubscriptionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8. | |
| Aplazada | Media (5.3) | 0.35% | — | Cozmoslabs Paid Member SubscriptionsAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9. | |
| Aplazada | Alta (7.5) | 0.56% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows PHP Local File Inclusion.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.4. | |
| Aplazada | Alta (7.5) | 0.27% | — | Cozmoslabs Paid Member SubscriptionsAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Paid Member SubscriptionsAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Stored XSS.This issue affects Paid Member Subscriptions: from n/a through <= 2.14.3. | |
| Analizada | Crítica (9.8) | 0.56% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 14/1/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the… | |
| Analizada | Media (5.3) | 0.48% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 18/12/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract… | |
| Analizada | Alta (7.3) | 0.46% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 9/11/2024 | 17/6/2026 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a… | |
| Analizada | Media (6.1) | 0.39% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 2/10/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.20% | — | Cozmoslabs Paid Member SubscriptionsAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0. | |
| Modificada | Media (4.3) | 0.53% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 29/2/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible… | |
| Modificada | Media (5.3) | 0.52% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 29/2/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1.… | |
| Modificada | Alta (8.8) | 1.7% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 13/9/2021 | 17/6/2026 | The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages. |