Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Cozmoslabs Paid Membership SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | |
| Aplazada | Baja (3.7) | 0.15% | — | Paidmembershipssubscriptions Paid Memberships SubscriptionsAI | 23/9/2026 | 23/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | |
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Media (4.3) | 0.17% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making. | |
| Aplazada | Media (5.3) | 0.34% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Flexible SubscriptionsAI | 19/8/2026 | 20/8/2026 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | |
| Aplazada | Crítica (9.8) | 0.96% | — | Woocommerce SubscriptionsAI | 12/8/2026 | 26/8/2026 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled… | |
| Aplazada | Baja (3.7) | 0.24% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal… | |
| Aplazada | Media (5.3) | 0.29% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full… | |
| Aplazada | Media (5.9) | 0.16% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without… | |
| Aplazada | Alta (8.8) | 0.64% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack… | |
| Aplazada | Media (4.3) | 0.27% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that… | |
| Aplazada | Media (5.4) | 0.29% | — | Cozmoslabs Paid Membership SubscriptionsAI | 4/8/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its… | |
| Aplazada | Alta (8.8) | 0.81% | — | Subscriptions FOR WoocommerceAI | 1/8/2026 | 12/8/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only… | |
| Aplazada | Baja (3.7) | 0.28% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present. | |
| Aplazada | Media (4.3) | 0.27% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. | |
| Aplazada | Alta (7.2) | 0.58% | — | Subscriptions FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.35% | — | Paid Member SubscriptionsAI | 27/7/2026 | 27/7/2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Paid Member SubscriptionsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Subscriptions FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paid Member SubscriptionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Subscriptions FOR WoocommerceAI | 18/3/2026 | 17/6/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any… | |
| Aplazada | Media (6.5) | 0.36% | — | Cozmoslabs Paid Member SubscriptionsAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8. |