Description
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Membership Pro prior to version 4.6.2 allows unauthenticated users to upload media assets by default. This flaw permits an attacker to upload any media file, which can then be accessed by other users or processed by the server, potentially affecting the site’s integrity. The vulnerability is a classic example of insecure default configuration (CWE-1188) that permits unauthorized access to a critical function.

Affected Systems

The affected product is the Membership Pro extension for Joomla by joomdonation.com. All installations running a version prior to 4.6.2 are impacted and need to be evaluated for this default configuration.

Risk and Exploitability

The CVSS score of 9.1 classifies this as Critical, and the EPSS score of less than 1% indicates that while exploitation opportunities are currently low, the high severity warrants immediate action. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this vulnerability by simply uploading a file from any unauthenticated session, assuming the server accepts or serves the uploaded content without proper validation.

Generated by OpenCVE AI on August 3, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Membership Pro extension to version 4.6.2 or later
  • Check and disable media asset upload for unauthenticated users in the extension’s configuration
  • Verify that the web server requires authentication for file upload endpoints and restrict allowed MIME types

Generated by OpenCVE AI on August 3, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomdonation.com
Joomdonation.com membership Pro Extension For Joomla
Vendors & Products Joomdonation.com
Joomdonation.com membership Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
Title Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2
Weaknesses CWE-1188
References

Subscriptions

Joomdonation.com Membership Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T15:01:08.350Z

Reserved: 2026-07-14T05:16:10.070Z

Link: CVE-2026-62415

cve-icon Vulnrichment

Updated: 2026-07-21T16:06:59.911Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:15:03Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default