Unrestricted File Upload Vulnerability in Joomla Membership Pro Extension
CVE-2026-62415

Currently unrated

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62415?

A significant security flaw exists in the Joomla extension Membership Pro prior to version 4.6.2, where unauthenticated users can upload media assets without proper validation. This oversight can lead to unauthorized access and exploitation of the system by allowing malicious files to be uploaded, posing risks to website integrity and user data.

Affected Version(s)

Membership Pro extension for Joomla 1.0-4.6.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.