Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 11 de 47

Media

WordPress · Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

CVE-2026-11592: CWE-862: Falta de autorización en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress. Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: 0 hasta 5.9.27

Leer análisis →
Media

WordPress · Product Video Gallery for Woocommerce

CVE-2026-10104: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Product Video Gallery for Woocommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Product Video Gallery for Woocommerce. Product Video Gallery for Woocommerce: 0 hasta 1.5.1.8

Leer análisis →
Media

WordPress · Kali Forms — Contact Form & Drag-and-Drop Builder

CVE-2026-9107: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Kali Forms — Contact Form & Drag-and-Drop Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Kali Forms — Contact Form & Drag-and-Drop Builder. Kali Forms — Contact Form & Drag-and-Drop Builder: 0 hasta 2.4.13

Leer análisis →
Alta

WordPress · Custom Payment Gateways for WooCommerce

CVE-2026-7517: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Custom Payment Gateways for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Custom Payment Gateways for WooCommerce. Custom Payment Gateways for WooCommerce: 0 hasta 2.1.0

Leer análisis →
Media

WordPress · Shortcodes and extra features for Phlox theme

CVE-2026-57737: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Shortcodes and extra features for Phlox theme

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Shortcodes and extra features for Phlox theme. Shortcodes and extra features for Phlox theme: n/a hasta 2.17.16

Leer análisis →
Alta

WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

CVE-2026-13731: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.4.9

Leer análisis →
Media

WordPress · Tutor LMS – eLearning and online course solution

CVE-2026-13443: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Tutor LMS – eLearning and online course solution

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 3.9.13

Leer análisis →
Media

WordPress · GiveWP – Donation Plugin and Fundraising Platform

CVE-2026-13246: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en GiveWP – Donation Plugin and Fundraising Platform

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GiveWP – Donation Plugin and Fundraising Platform. GiveWP – Donation Plugin and Fundraising Platform: 0 hasta 4.16.0

Leer análisis →
Media

WordPress · Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-12904: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor. Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: 0 hasta 3.7.7

Leer análisis →
Media

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-12754: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.12

Leer análisis →
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-12732: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.4.0

Leer análisis →
Media

WordPress · Slim SEO – A Fast & Automated SEO Plugin For WordPress

CVE-2026-12408: CWE-200: Exposición de información sensible a un actor no autorizado en Slim SEO – A Fast & Automated SEO Plugin For WordPress

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Slim SEO – A Fast & Automated SEO Plugin For WordPress. Slim SEO – A Fast & Automated SEO Plugin For WordPress: 0 hasta 4.9.8

Leer análisis →
Alta

WordPress · RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-12158: CWE-352: vulnerabilidad de seguridad en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: 0 hasta 6.0.9.1

Leer análisis →
Alta

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-12142: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.2.2

Leer análisis →
Media

WordPress · WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

CVE-2026-12127: CWE-93: vulnerabilidad de seguridad en WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

El registro oficial identifica la vulnerabilidad «CWE-93: vulnerabilidad de seguridad» en WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More. WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More: 0 hasta 1.10.2

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12110: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.8

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12090: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.8

Leer análisis →
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-11988: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.3.9.1

Leer análisis →
Crítica

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-11387: CWE-287: Autenticación incorrecta en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.5

Leer análisis →
Crítica

WordPress · EventON (Pro) - WordPress Virtual Event Calendar Plugin

CVE-2026-9711: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en EventON (Pro) - WordPress Virtual Event Calendar Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en EventON (Pro) - WordPress Virtual Event Calendar Plugin. EventON (Pro) - WordPress Virtual Event Calendar Plugin: 0 hasta 5.0.11

Leer análisis →
Media

WordPress · Editorial Rating – Product Review & Rating System

CVE-2026-12560: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Editorial Rating – Product Review & Rating System

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Editorial Rating – Product Review & Rating System. Editorial Rating – Product Review & Rating System: 0 hasta 4.0.5

Leer análisis →
Media

WordPress · Team Members – Multi Language Supported Team Plugin

CVE-2026-12114: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Team Members – Multi Language Supported Team Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Team Members – Multi Language Supported Team Plugin. Team Members – Multi Language Supported Team Plugin: 0 hasta 8.7

Leer análisis →
Crítica

WordPress · ProfileGrid – User Profiles, Groups and Communities

CVE-2026-12073: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ProfileGrid – User Profiles, Groups and Communities

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ProfileGrid – User Profiles, Groups and Communities. ProfileGrid – User Profiles, Groups and Communities: 0 hasta 5.9.9.5

Leer análisis →
Media

WordPress · Colissimo Officiel : Méthodes de livraison pour WooCommerce

CVE-2026-57341: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Colissimo Officiel : Méthodes de livraison pour WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Colissimo Officiel : Méthodes de livraison pour WooCommerce. Colissimo Officiel : Méthodes de livraison pour WooCommerce: n/a hasta 2.9.0

Leer análisis →
Media

WordPress · RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-9242: CWE-345: vulnerabilidad de seguridad en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: 0 hasta 6.0.8.6

Leer análisis →