Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Wclovers Wcfm MembershipAI | 4/9/2026 | 4/9/2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wclovers Wcfm MembershipAI | 3/9/2026 | 7/9/2026 | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | |
| Aplazada | Alta (8.1) | 0.40% | — | Wclovers Wcfm MembershipAI | 8/7/2026 | 8/7/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it… | |
| Aplazada | Alta (7.3) | 0.30% | — | Wclovers Wcfm MembershipAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10. | |
| Aplazada | Media (4.3) | 0.27% | — | Wclovers Wcfm MembershipAI | 10/2/2026 | 17/6/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it… | |
| Modificada | Crítica (9.8) | 1.1% | — | Wclovers Wcfm Membership | 20/5/2023 | 17/6/2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system… | |
| Modificada | Alta (8.8) | 0.32% | — | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing… | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying… | |
| Modificada | Crítica (9.8) | 2.1% | 💥 PoC | Wclovers Wcfm Membership | 5/4/2023 | 17/6/2026 | THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the… |