Wishlistmember
Wishlistmember Wishlist Member: vulnerabilidades y CVE
Wishlistmember Wishlist Member tiene 8 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses7
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12949 | Crítica (9.8) | 0.53% | — | 14 ago 2026 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating… |
| CVE-2026-25446 | Crítica (9.9) | 0.48% | — | 17 jun 2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. |
| CVE-2026-24575 | Media (4.3) | 0.26% | — | 17 jun 2026 | Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. |
| CVE-2026-6898 | Alta (8.8) | 0.44% | — | 23 may 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and… |
| CVE-2026-6897 | Alta (8.8) | 0.44% | — | 23 may 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to,… |
| CVE-2026-6895 | Alta (8.8) | 0.45% | — | 23 may 2026 | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing… |
| CVE-2026-6419 | Alta (8.8) | 0.44% | — | 23 may 2026 | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the… |
| CVE-2024-37109 | Alta (8.8) | 0.53% | — | 24 jun 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.