Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.26%—Strangerstudios Paid Memberships PROAI28/7/202628/7/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output…
AplazadaAlta (7.5)0.39%—Paidmembershipspro Paid Memberships PROAI24/7/202624/7/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the…
AplazadaAlta (8.8)0.20%—Paidmembershipspro Paid Memberships PROAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
AplazadaAlta (7.1)0.37%—Paidmembershipspro Paid Memberships PROAI2/5/202617/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and…
AnalizadaCrítica (9.8)0.67%—Strangerstudios Paid Memberships PRO1/11/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
ModificadaMedia (6.5)0.52%—Strangerstudios Paid Memberships PRO30/7/202417/6/2026
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
AnalizadaMedia (4.9)0.56%—Strangerstudios Paid Memberships PRO30/7/202417/6/2026
The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.
ModificadaAlta (7.2)0.74%—Strangerstudios Paid Memberships PRO9/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
AnalizadaAlta (8.8)0.48%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
ModificadaMedia (5.4)0.22%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated…
ModificadaMedia (4.3)0.30%—Strangerstudios Paid Memberships PRO2/5/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it…
ModificadaAlta (8.8)0.24%—Strangerstudios Paid Memberships PRO24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
ModificadaAlta (8.8)0.23%—Strangerstudios Paid Memberships PRO24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
ModificadaMedia (4.3)0.90%💥 PoCStrangerstudios Paid Memberships PRO9/4/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible…
ModificadaMedia (4.3)0.55%—Strangerstudios Paid Memberships PRO11/3/202417/6/2026
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
ModificadaMedia (5.3)0.95%💥 PoCStrangerstudios Paid Memberships PRO25/1/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible…
ModificadaMedia (5.3)0.51%—Strangerstudios Paid Memberships PRO11/1/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up…
ModificadaAlta (8.8)51%—Strangerstudios Paid Memberships PRO18/11/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or…
ModificadaMedia (4.3)0.39%—Strangerstudios Paid Memberships PRO20/10/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they…
ModificadaAlta (8.8)60%—Strangerstudios Paid Memberships PRO20/3/202317/6/2026
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
ModificadaMedia (5.4)65%—Strangerstudios Paid Memberships PRO13/2/202317/6/2026
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaCrítica (9.8)92%💥 ExploitStrangerstudios Paid Memberships PRO20/1/202317/6/2026
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
ModificadaCrítica (9.8)82%💥 ExploitStrangerstudios Paid Memberships PRO7/2/202217/6/2026
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
ModificadaMedia (6.1)1.9%💥 ExploitStrangerstudios Paid Memberships PRO27/12/202117/6/2026
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)2.0%—Strangerstudios Paid Memberships PRO18/3/202117/6/2026
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Orbitaley — Vulnerabilidades