Executive brief
Membership Pro is a popular Joomla extension used to manage paid subscriptions and restrict access to website content. A security flaw in versions prior to 4.6.2 allowed any website visitor, even those without an account, to upload media files to the server by default. This could lead to unauthorized storage usage or the hosting of malicious content on the affected website.
Technical details
A vulnerability classified as Insecure Default Initialization of Resource (CWE-1188) exists in the Membership Pro extension for Joomla. In versions prior to 4.6.2, the default configuration failed to restrict media asset uploads to authenticated or authorized users. An unauthenticated remote attacker could exploit this by sending upload requests to the affected component, potentially leading to arbitrary file uploads or resource exhaustion. The issue was addressed in version 4.6.2 by hardening the default upload permissions.
Affected products
- joomdonation.com Membership Pro extension for Joomla 1.0 through 4.6.1
Timeline
- 2026-07-21: advisory: CVE-2026-62415 published by the Joomla! Project
- 2026-07-21: patched: Version 4.6.2 released to address the issue