Security
Membership Pro 4.6.2 fixes critical anonymous upload flaw
JoomDonation has released Membership Pro 4.6.2 to address a critical unauthenticated file upload vulnerability affecting versions through 4.6.1.
Security researchers at mySites.guru say the flaw allowed anonymous visitors to upload files to Joomla sites running Membership Pro, including installations that did not use File custom fields. The issue is tracked as CVE-2026-62415 and has a critical 9.1 rating.
JoomDonation’s release describes the change as improved file-upload handling. In 4.6.2, the upload endpoint is disabled when no File custom fields are configured, while sites that use the feature receive additional checks. The release also includes a cleanup tool for unauthenticated upload files left behind before the update.
mySites.guru reports no confirmed exploitation of Membership Pro in its write-up. The research links the issue to a similar flaw previously reported in another JoomDonation extension, Events Booking, while noting that Membership Pro was not audited line by line.
- Versions
4.6.1and earlier are affected. - Update to
4.6.2immediately. - Run the included cleanup tool after updating; a scheduled-task version is also available.
Originally reported by mySites.guru.