Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 1 de 47

Media

WordPress · MasterStudy LMS WordPress Plugin – for Online Courses and Education

CVE-2026-5060: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en MasterStudy LMS WordPress Plugin – for Online Courses and Education

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en MasterStudy LMS WordPress Plugin – for Online Courses and Education. MasterStudy LMS WordPress Plugin – for Online Courses and Education: 0 hasta 3.7.23

Leer análisis →
Crítica

WordPress · Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …

CVE-2026-18072: CWE-506: vulnerabilidad de seguridad en Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …

El registro oficial identifica la vulnerabilidad «CWE-506: vulnerabilidad de seguridad» en Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …. Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …: 10.8.7

Leer análisis →
Media

WordPress · Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

CVE-2026-17166: CWE-862: Falta de autorización en Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar. Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar: 0 hasta 5.3.7

Leer análisis →
Media

WordPress · WowStore – Store Builder & Product Blocks for WooCommerce

CVE-2026-17162: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WowStore – Store Builder & Product Blocks for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WowStore – Store Builder & Product Blocks for WooCommerce. WowStore – Store Builder & Product Blocks for WooCommerce: 0 hasta 4.4.24

Leer análisis →
Media

WordPress · WowStore – Store Builder & Product Blocks for WooCommerce

CVE-2026-17161: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WowStore – Store Builder & Product Blocks for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WowStore – Store Builder & Product Blocks for WooCommerce. WowStore – Store Builder & Product Blocks for WooCommerce: 0 hasta 4.4.24

Leer análisis →
Alta

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-16655: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.2.7

Leer análisis →
Alta

WordPress · GTM4WP – A Google Tag Manager (GTM) plugin for WordPress

CVE-2026-16597: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en GTM4WP – A Google Tag Manager (GTM) plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GTM4WP – A Google Tag Manager (GTM) plugin for WordPress. GTM4WP – A Google Tag Manager (GTM) plugin for WordPress: 0 hasta 1.22.3

Leer análisis →
Sin clasificar

WordPress · miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)

CVE-2026-14300: CWE-287: Autenticación incorrecta en miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn). miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn): 0 hasta 7.8.0

Leer análisis →
Alta

WordPress · Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

CVE-2026-12476: CWE-434: vulnerabilidad de seguridad en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy. Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 0 hasta 3.6.9

Leer análisis →
Media

WordPress · SpeedyCache – Cache, Optimization, Performance

CVE-2026-5114: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en SpeedyCache – Cache, Optimization, Performance

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en SpeedyCache – Cache, Optimization, Performance. SpeedyCache – Cache, Optimization, Performance: 0 hasta 1.3.8

Leer análisis →
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-16811: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5

Leer análisis →
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-16797: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5

Leer análisis →
Media

WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

CVE-2026-16773: CWE-200: Exposición de información sensible a un actor no autorizado en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.5.9

Leer análisis →
Alta

WordPress · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

CVE-2026-16585: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots. Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots: 0 hasta 2.15.19

Leer análisis →
Media

WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

CVE-2026-15730: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.9.1

Leer análisis →
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15673: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis →
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15671: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis →
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15670: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis →
Media

WordPress · Tutor LMS – eLearning and online course solution

CVE-2026-15444: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Tutor LMS – eLearning and online course solution

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 4.0.1

Leer análisis →
Media

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-15411: CWE-862: Falta de autorización en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis →
Media

WordPress · Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

CVE-2026-15393: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates. Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates: 0 hasta 2.2.11

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-15267: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.9

Leer análisis →
Media

WordPress · WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

CVE-2026-15136: CWE-352: vulnerabilidad de seguridad en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode. WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: 0 hasta 4.3.7

Leer análisis →
Alta

WordPress · Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

CVE-2026-15025: CWE-862: Falta de autorización en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: 0 hasta 7.3.2

Leer análisis →
Media

WordPress · Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

CVE-2026-15016: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions. Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: 0 hasta 3.8.1

Leer análisis →
Crítica

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15014: CWE-288: vulnerabilidad de seguridad en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-288: vulnerabilidad de seguridad» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis →
Media

WordPress · Demi – One Click Demo Import, Backup & Site Migration

CVE-2026-15012: CWE-200: Exposición de información sensible a un actor no autorizado en Demi – One Click Demo Import, Backup & Site Migration

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Demi – One Click Demo Import, Backup & Site Migration. Demi – One Click Demo Import, Backup & Site Migration: 0 hasta 0.0.8

Leer análisis →
Alta

WordPress · Online Scheduling and Appointment Booking System – Bookly

CVE-2026-14516: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Online Scheduling and Appointment Booking System – Bookly

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Online Scheduling and Appointment Booking System – Bookly. Online Scheduling and Appointment Booking System – Bookly: 0 hasta 27.5

Leer análisis →
Alta

WordPress · Demi – One Click Demo Import, Backup & Site Migration

CVE-2026-14490: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Demi – One Click Demo Import, Backup & Site Migration

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Demi – One Click Demo Import, Backup & Site Migration. Demi – One Click Demo Import, Backup & Site Migration: 0 hasta 0.0.7

Leer análisis →
Alta

WordPress · Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

CVE-2026-14328: CWE-269: Gestión incorrecta de privilegios en Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress. Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress: 0 hasta 4.4.1

Leer análisis →
Alta

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-13440: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis →
Alta

WordPress · TrueBooker – Appointment Booking and Scheduler System

CVE-2026-13161: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en TrueBooker – Appointment Booking and Scheduler System

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en TrueBooker – Appointment Booking and Scheduler System. TrueBooker – Appointment Booking and Scheduler System: 0 hasta 1.2.2

Leer análisis →
Media

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-13110: CWE-862: Falta de autorización en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis →
Alta

WordPress · Premium Packages – Sell Digital Products Securely

CVE-2026-12800: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Premium Packages – Sell Digital Products Securely

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Premium Packages – Sell Digital Products Securely. Premium Packages – Sell Digital Products Securely: 0 hasta 6.2.0

Leer análisis →
Alta

WordPress · WP Fast Total Search – The Power of Indexed Search

CVE-2026-12741: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Fast Total Search – The Power of Indexed Search

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Fast Total Search – The Power of Indexed Search. WP Fast Total Search – The Power of Indexed Search: 0 hasta 1.80.280

Leer análisis →
Media

WordPress · PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer

CVE-2026-12124: CWE-862: Falta de autorización en PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer. PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer: 0 hasta 1.1.0

Leer análisis →
Media

WordPress · Checkout Field Editor for WooCommerce – Checkout Manager

CVE-2026-66475: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Checkout Field Editor for WooCommerce – Checkout Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Checkout Field Editor for WooCommerce – Checkout Manager. Checkout Field Editor for WooCommerce – Checkout Manager: n/a hasta 3.0.5

Leer análisis →
Media

WordPress · Photonic Gallery & Lightbox for Flickr, SmugMug & Others

CVE-2026-66434: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Photonic Gallery & Lightbox for Flickr, SmugMug & Others

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Photonic Gallery & Lightbox for Flickr, SmugMug & Others. Photonic Gallery & Lightbox for Flickr, SmugMug & Others: n/a hasta 3.33

Leer análisis →
Media

WordPress · Anti Spam and list cleaner – AcyChecker

CVE-2026-65448: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Anti Spam and list cleaner – AcyChecker

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Anti Spam and list cleaner – AcyChecker. Anti Spam and list cleaner – AcyChecker: n/a hasta 1.8.1

Leer análisis →