Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 1.0% | — | S2memberAI | 25/9/2026 | 25/9/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name… | |
| Aplazada | Media (6.8) | 0.43% | — | S2memberAI | 10/8/2026 | 26/8/2026 | The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS). | |
| Aplazada | Crítica (9.8) | 0.38% | — | S2memberAI | 19/2/2026 | 17/6/2026 | The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary… | |
| Aplazada | Media (6.4) | 0.32% | — | S2memberAI | 19/2/2026 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Crítica (9.8) | 0.47% | — | S2member Project S2memberAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701. | |
| Aplazada | Crítica (9) | 0.42% | — | Cristian Lavaque S2memberAI | 22/10/2025 | 29/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905. | |
| Aplazada | Media (4.9) | 0.78% | — | S2memberAI | 4/4/2025 | 17/6/2026 | Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2Member: from n/a through <= 250419. | |
| Aplazada | Alta (8.8) | 0.63% | — | S2member PROAI | 18/3/2025 | 17/6/2026 | The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the… | |
| Aplazada | Alta (7.1) | 0.32% | — | Cristian Lavaque S2memberAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216. | |
| Analizada | Media (6.1) | 0.43% | — | Clavaque S2member | 18/2/2025 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it… | |
| Analizada | Crítica (9.8) | 0.95% | — | S2member | 15/2/2025 | 17/6/2026 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… | |
| Aplazada | Alta (8.8) | 0.58% | — | S2memberAI | 17/12/2024 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9) | 0.47% | — | Cristian Lavaque S2memberAI | 6/12/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affects s2Member: from n/a through <= 241114. | |
| Aplazada | Alta (7.5) | 0.42% | — | WP Sharks S2member PROAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315. | |
| Aplazada | Media (5.3) | 0.56% | — | S2memberAI | 9/4/2024 | 17/6/2026 | The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of… | |
| Modificada | Media (4.3) | 1.9% | — | S2member | 19/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field). |