Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 20 de 47

Media

WordPress · Tiled Gallery Carousel Without JetPack

CVE-2026-5191: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Tiled Gallery Carousel Without JetPack

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Tiled Gallery Carousel Without JetPack. Tiled Gallery Carousel Without JetPack: 0 hasta 3.1

Leer análisis →
Crítica

WordPress · ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5076: CWE-287: Autenticación incorrecta en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup. ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: 0 hasta 7.3.1

Leer análisis →
Media

WordPress · ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5074: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup. ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: 0 hasta 7.3.1

Leer análisis →
Alta

WordPress · ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-5073: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup. ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: 0 hasta 7.3.1

Leer análisis →
Media

WordPress · Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)

CVE-2026-3722: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO). Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO): 0 hasta 4.9

Leer análisis →
Alta

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-42683: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: n/a hasta 1.8.8

Leer análisis →
Alta

WordPress · Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity

CVE-2026-42673: CWE-201: vulnerabilidad de seguridad en Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity

El registro oficial identifica la vulnerabilidad «CWE-201: vulnerabilidad de seguridad» en Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity. Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: n/a hasta 3.3.6

Leer análisis →
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-9243: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.15

Leer análisis →
Media

WordPress · Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

CVE-2026-8995: CWE-200: Exposición de información sensible a un actor no autorizado en Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls. Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls: 0 hasta 6.3.7

Leer análisis →
Media

WordPress · Post Snippets – Custom WordPress Code Snippets Customizer

CVE-2026-7430: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Post Snippets – Custom WordPress Code Snippets Customizer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Post Snippets – Custom WordPress Code Snippets Customizer. Post Snippets – Custom WordPress Code Snippets Customizer: 0 hasta 4.0.19

Leer análisis →
Media

WordPress · StatCounter – Free Real Time Visitor Stats

CVE-2026-6275: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en StatCounter – Free Real Time Visitor Stats

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StatCounter – Free Real Time Visitor Stats. StatCounter – Free Real Time Visitor Stats: 0 hasta 2.1.1

Leer análisis →
Media

WordPress · PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

CVE-2026-9618: CWE-352: vulnerabilidad de seguridad en PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI). PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI): 0 hasta 1.120.46

Leer análisis →
Media

WordPress · FOX – Currency Switcher Professional for WooCommerce

CVE-2026-9241: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en FOX – Currency Switcher Professional for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en FOX – Currency Switcher Professional for WooCommerce. FOX – Currency Switcher Professional for WooCommerce: 0 hasta 1.4.6

Leer análisis →
Media

WordPress · Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

CVE-2026-9015: CWE-862: Falta de autorización en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance. Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance: 0 hasta 1.42.0

Leer análisis →
Alta

WordPress · Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-7797: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: 0 hasta 1.6.11.8

Leer análisis →
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-7651: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.5

Leer análisis →
Media

WordPress · Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

CVE-2026-7533: CWE-352: vulnerabilidad de seguridad en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy. Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 0 hasta 3.6.7

Leer análisis →
Alta

WordPress · HT Contact Form – Drag & Drop Form Builder for WordPress

CVE-2026-7052: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en HT Contact Form – Drag & Drop Form Builder for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en HT Contact Form – Drag & Drop Form Builder for WordPress. HT Contact Form – Drag & Drop Form Builder for WordPress: 0 hasta 2.8.2

Leer análisis →
Media

WordPress · Photo Gallery by 10Web – Mobile-Friendly Image Gallery

CVE-2026-7048: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Photo Gallery by 10Web – Mobile-Friendly Image Gallery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Photo Gallery by 10Web – Mobile-Friendly Image Gallery. Photo Gallery by 10Web – Mobile-Friendly Image Gallery: 0 hasta 1.8.40

Leer análisis →
Media

WordPress · Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-6937: CWE-862: Falta de autorización en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: 0 hasta 1.6.11.8

Leer análisis →
Media

WordPress · Meta Field Block – Display custom fields in the Block Editor without coding

CVE-2026-3173: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Meta Field Block – Display custom fields in the Block Editor without coding

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Meta Field Block – Display custom fields in the Block Editor without coding. Meta Field Block – Display custom fields in the Block Editor without coding: 0 hasta 1.5.1

Leer análisis →
Media

WordPress · CM Ad Changer – A simple tool to control and optimize your site's banners

CVE-2026-9236: CWE-352: vulnerabilidad de seguridad en CM Ad Changer – A simple tool to control and optimize your site's banners

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en CM Ad Changer – A simple tool to control and optimize your site's banners. CM Ad Changer – A simple tool to control and optimize your site's banners: 0 hasta 2.0.7

Leer análisis →