« Volver al listado

Wishlistmember

Wishlistmember Wishlist Member: vulnerabilidades y CVE

Wishlistmember Wishlist Member tiene 8 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses7
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-12949Crítica (9.8)0.53%—14 ago 2026
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating…
CVE-2026-25446Crítica (9.9)0.48%—17 jun 2026
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
CVE-2026-24575Media (4.3)0.26%—17 jun 2026
Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
CVE-2026-6898Alta (8.8)0.44%—23 may 2026
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and…
CVE-2026-6897Alta (8.8)0.44%—23 may 2026
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to,…
CVE-2026-6895Alta (8.8)0.45%—23 may 2026
The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing…
CVE-2026-6419Alta (8.8)0.44%—23 may 2026
The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the…
CVE-2024-37109Alta (8.8)0.53%—24 jun 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1068 Exploitation for Privilege Escalation2
  3. T1552.007 Container API2
  4. T1098.002 Additional Email Delegate Permissions1
  5. T1190 Exploit Public-Facing Application1
  6. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wishlistmember