CVE-2026-62415
A Joomla extension called Membership Pro had a default setting that let anyone upload files without logging in. This flaw could let attackers add malicious files to the site. The issue exists in versions before 4.6.2.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
The Joomla extension Membership Pro, versions earlier than 4.6.2, on Joomla-powered websites.
Real-world impact
An attacker could upload arbitrary files, such as malware or scripts, to the site, potentially leading to site compromise or defacement.
Why this severity
The CVSS score of 9.1 reflects that the flaw is easy to exploit (no authentication or user interaction needed) and can give attackers full control over the site’s files, causing significant damage.
What to do about it
- 01Upgrade the Membership Pro extension to version 4.6.2 or later to remove the insecure default upload setting.
NVD description
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.