Wpswings
Wpswings Membership FOR Woocommerce: vulnerabilidades y CVE
Wpswings Membership FOR Woocommerce tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19709 | Media (5.3) | 0.32% | — | 19 ago 2026 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated… |
| CVE-2026-57709 | Alta (8.6) | 0.53% | — | 13 jul 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For… |
| CVE-2025-67909 | Alta (7.5) | 0.39% | — | 24 dic 2025 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… |
| CVE-2025-54692 | Alta (7.5) | 0.36% | — | 14 ago 2025 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from… |
| CVE-2025-49265 | Alta (7.5) | 0.34% | — | 9 jun 2025 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from… |
| CVE-2025-39579 | Media (6.5) | 0.32% | — | 16 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows DOM-Based XSS.This issue affects Membership… |
| CVE-2022-4395 | Crítica (9.8) | 18% | — | 30 ene 2023 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpswings
Wallet System FOR Woocommerce · 11Return Refund AND Exchange FOR Woocommerce · 7Ultimate Gift Cards FOR Woocommerce · 6Points AND Rewards FOR Woocommerce · 4Woocommerce Ultimate Gift Card · 3Coupon Referral Program · 2PDF Generator FOR Wordpress · 2Subscriptions FOR Woocommerce · 2ONE Click Upsell Funnel FOR Woocommerce · 1Woocommerce Ultimate Points AND Rewards · 1Mautic Integration FOR Woocommerce · 1Upsell Order Bump Offer FOR Woocommerce · 1