Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 14 de 47

Alta

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-7761: CWE-862: Falta de autorización en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.11.4

Leer análisis →
Sin clasificar

WordPress · Linux

CVE-2026-53038: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta 081b557cb56e1cfa8d1619b2601b01c53e3f418c, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta b6766b171a5c4c33b26ff6fec530cb798db1f75e, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta 88d4e89a39f0de07798ca3fd93bd1a9ea212a82e, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta d7bd8cf0b348d3edae7bee33e74a32b21668b181; Linux: 6.10, 0 hasta 6.10, 6.12.91 hasta 6.12.*, 6.18.33 hasta 6.18.*, 7.0.10 hasta 7.0.*, 7.1 hasta *

Leer análisis →
Media

WordPress · Xpro Addons — 140+ Widgets for Elementor

CVE-2026-11614: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Xpro Addons — 140+ Widgets for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Xpro Addons — 140+ Widgets for Elementor. Xpro Addons — 140+ Widgets for Elementor: 0 hasta 1.7.2

Leer análisis →
Alta

WordPress · smart-post-show-pro / Real Testimonials Pro / Product Slider for WooCommerce Pro

CVE-2026-10735: CWE-912: vulnerabilidad de seguridad en smart-post-show-pro / Real Testimonials Pro / Product Slider for WooCommerce Pro

El registro oficial identifica la vulnerabilidad «CWE-912: vulnerabilidad de seguridad» en smart-post-show-pro / Real Testimonials Pro / Product Slider for WooCommerce Pro. smart-post-show-pro: 4.0.1 hasta 4.0.2; Real Testimonials Pro: 3.2.4 hasta 3.2.5; Product Slider for WooCommerce Pro: 3.5.2 hasta 3.5.3

Leer análisis →
Media

WordPress · ProfileGrid – User Profiles, Groups and Communities

CVE-2026-4610: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en ProfileGrid – User Profiles, Groups and Communities

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en ProfileGrid – User Profiles, Groups and Communities. ProfileGrid – User Profiles, Groups and Communities: 0 hasta 5.9.9.2

Leer análisis →
Alta

WordPress · Database for Contact Form 7, WPforms, Elementor forms

CVE-2026-9843: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Database for Contact Form 7, WPforms, Elementor forms

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Database for Contact Form 7, WPforms, Elementor forms. Database for Contact Form 7, WPforms, Elementor forms: 0 hasta 1.5.1

Leer análisis →
Media

WordPress · BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

CVE-2026-12157: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot. BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot: 0 hasta 4.5.3

Leer análisis →
Media

WordPress · Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation

CVE-2026-11989: CWE-918: vulnerabilidad de seguridad en Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation. Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation: 0 hasta 2.8.7

Leer análisis →
Media

WordPress · Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

CVE-2026-9199: CWE-862: Falta de autorización en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance. Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance: 0 hasta 1.42.1

Leer análisis →
Media

WordPress · SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager

CVE-2026-12137: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager. SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager: 0 hasta 4.3.6

Leer análisis →
Media

WordPress · SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager

CVE-2026-12136: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager. SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager: 0 hasta 4.3.6

Leer análisis →
Media

WordPress · FireBox Popups – Increase Sales and Grow Your Email List

CVE-2026-12120: CWE-200: Exposición de información sensible a un actor no autorizado en FireBox Popups – Increase Sales and Grow Your Email List

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en FireBox Popups – Increase Sales and Grow Your Email List. FireBox Popups – Increase Sales and Grow Your Email List: 0 hasta 3.1.7

Leer análisis →
Baja

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-12102: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.63

Leer análisis →
Media

WordPress · PowerPress Podcasting plugin by Blubrry

CVE-2026-12098: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en PowerPress Podcasting plugin by Blubrry

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en PowerPress Podcasting plugin by Blubrry. PowerPress Podcasting plugin by Blubrry: 0 hasta 11.16.8

Leer análisis →
Media

WordPress · Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

CVE-2026-11784: CWE-352: vulnerabilidad de seguridad en Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization. Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization: 0 hasta 4.2.6

Leer análisis →
Media

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-11777: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.43

Leer análisis →
Media

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-11776: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.43

Leer análisis →
Media

WordPress · Services Section Block – Showcase Service Details in Grid or Columns

CVE-2026-11402: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Services Section Block – Showcase Service Details in Grid or Columns

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Services Section Block – Showcase Service Details in Grid or Columns. Services Section Block – Showcase Service Details in Grid or Columns: 0 hasta 1.4.4

Leer análisis →
Media

WordPress · Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

CVE-2026-11358: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More. Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: 0 hasta 3.0.6

Leer análisis →
Media

WordPress · Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-11357: CWE-200: Exposición de información sensible a un actor no autorizado en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor. Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: 0 hasta 3.7.5

Leer análisis →
Media

WordPress · Tutor LMS – eLearning and online course solution

CVE-2026-10736: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Tutor LMS – eLearning and online course solution

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 3.9.11

Leer análisis →
Media

WordPress · PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin

CVE-2026-10623: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin. PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin: 0 hasta 2.3.0

Leer análisis →
Media

WordPress · Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

CVE-2026-10023: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: 0 hasta 5.0.3

Leer análisis →
Media

WordPress · Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

CVE-2026-8607: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred. Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred: 0 hasta 3.1

Leer análisis →
Alta

WordPress · weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce

CVE-2026-8089: CWE-79: Cross-Site Scripting (XSS) en weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce. weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce: 0 hasta 2.1.3

Leer análisis →