Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Membership Pro security vulnerabilities

mySites.guru tracks 1 vulnerability in Membership Pro (com_osmembership), covering 1 CVE. Every connected Joomla site is checked against it on each audit.

Is my site affected?

Your site is affected if it runs Membership Pro in this range:

  • before 4.6.2
Latest safe version
4.6.2 or later. No rule we check matches that release or any newer one.
What to do
Update Membership Pro to 4.6.2 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every Membership Pro vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-62415CVSS 9.1before 4.6.24.6.2Medium2026-07-21

What we check for

MediumCVE-2026-624152026-07-21

Membership Pro (com_osmembership) below 4.6.2 - Unauthenticated File Upload

Membership Pro versions below 4.6.2 expose an unauthenticated file upload endpoint used by subscribers during the subscription process when the site uses File custom fields. This is the same class of unauthenticated upload flaw found in Events Booking from the same developer (JoomDonation / Ossolution), which mySites.guru documented at https://mysites.guru/blog/events-booking-unauthenticated-upload-user-enumeration/. In 4.6.2 (released 2026-07-21) the upload endpoint is automatically disabled when the site uses no File custom fields, and when File custom fields are in use additional validation and abuse protection have been added. The vendor classifies the issue as abuse of upload storage (anonymous users filling hosting space with unwanted files) rather than remote code execution, and states attackers could not upload executable files, steal data, or take control of the site. Fix: update to 4.6.2 or later. After updating, run the Membership Pro cleanup tool to delete any unauthenticated upload files left behind before the update, and optionally configure the new scheduled task to clean them up going forward.

Affected versions: < 4.6.2

Full advisory: our disclosure post

Timeline

  1. 21 July 2026Check added for CVE-2026-62415 (before 4.6.2)
  2. 21 July 2026CVE-2026-62415 record published
  3. 21 July 2026We published: Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

What we have written about Membership Pro

References

Each CVE page above links its official cve.org record and its NVD entry.

Membership Pro vulnerability questions

Which versions of Membership Pro are vulnerable?
mySites.guru tracks one vulnerability in Membership Pro (com_osmembership). A site is affected if its installed version is in this range: before 4.6.2.
What is the latest safe version of Membership Pro?
4.6.2. Every vulnerability tracked here is fixed by 4.6.2, and no rule we check matches that release or any later one.
How do I check which version of Membership Pro my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for com_osmembership. mySites.guru reads the installed version on every audit of a connected site and checks it against this rule.

Running Membership Pro on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-62415. Rules current as of 5 October 2026.