Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 23 de 47

Media

WordPress · Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

CVE-2026-6566: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery. Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery: 0 hasta 4.2.0

Leer análisis →
Media

WordPress · Anomify AI – Anomaly Detection and Alerting

CVE-2026-6404: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Anomify AI – Anomaly Detection and Alerting

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Anomify AI – Anomaly Detection and Alerting. Anomify AI – Anomaly Detection and Alerting: 0 hasta 0.3.6

Leer análisis →
Media

WordPress · Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

CVE-2026-6394: CWE-918: vulnerabilidad de seguridad en Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE. Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: 0 hasta 1.1.1

Leer análisis →
Media

WordPress · 診断ジェネレータ作成プラグイン

CVE-2026-5293: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en 診断ジェネレータ作成プラグイン

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en 診断ジェネレータ作成プラグイン. 診断ジェネレータ作成プラグイン: 0 hasta 1.4.16

Leer análisis →
Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-5200: CWE-862: Falta de autorización en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 10.8.2

Leer análisis →
Media

WordPress · All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic

CVE-2026-5075: CWE-200: Exposición de información sensible a un actor no autorizado en All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic. All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic: 0 hasta 4.9.7

Leer análisis →
Alta

WordPress · Creative Mail – Easier WordPress & WooCommerce Email Marketing

CVE-2026-3985: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Creative Mail – Easier WordPress & WooCommerce Email Marketing

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Creative Mail – Easier WordPress & WooCommerce Email Marketing. Creative Mail – Easier WordPress & WooCommerce Email Marketing: 0 hasta 1.6.9

Leer análisis →
Media

WordPress · AI Chatbot & Workflow Automation by AIWU

CVE-2026-2955: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en AI Chatbot & Workflow Automation by AIWU

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en AI Chatbot & Workflow Automation by AIWU. AI Chatbot & Workflow Automation by AIWU: 0 hasta 1.4.14

Leer análisis →
Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-8912: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 28.1.6

Leer análisis →
Media

WordPress · Classified Listing – AI-Powered Classified ads & Business Directory Plugin

CVE-2026-7563: CWE-862: Falta de autorización en Classified Listing – AI-Powered Classified ads & Business Directory Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Classified Listing – AI-Powered Classified ads & Business Directory Plugin. Classified Listing – AI-Powered Classified ads & Business Directory Plugin: 0 hasta 5.3.10

Leer análisis →
Media

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-7046: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.1.12

Leer análisis →
Media

WordPress · The7 — Website and eCommerce Builder for WordPress

CVE-2026-6646: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The7 — Website and eCommerce Builder for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The7 — Website and eCommerce Builder for WordPress. The7 — Website and eCommerce Builder for WordPress: 0 hasta 14.3.2

Leer análisis →
Media

WordPress · Advanced Custom Fields: Font Awesome Field

CVE-2026-6415: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Advanced Custom Fields: Font Awesome Field

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Advanced Custom Fields: Font Awesome Field. Advanced Custom Fields: Font Awesome Field: 0 hasta 5.0.2

Leer análisis →
Crítica

WordPress · Receive Notifications After Form Submitting – Form Notify for Any Forms

CVE-2026-5229: CWE-287: Autenticación incorrecta en Receive Notifications After Form Submitting – Form Notify for Any Forms

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Receive Notifications After Form Submitting – Form Notify for Any Forms. Receive Notifications After Form Submitting – Form Notify for Any Forms: 0 hasta 1.1.10

Leer análisis →
Crítica

WordPress · Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)

CVE-2026-8181: CWE-287: Autenticación incorrecta en Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative). Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative): 3.4.0 hasta 3.4.1.1

Leer análisis →
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-7648: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.3.5

Leer análisis →
Media

WordPress · Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-6504: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Royal Addons for Elementor – Addons and Templates Kit for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Royal Addons for Elementor – Addons and Templates Kit for Elementor. Royal Addons for Elementor – Addons and Templates Kit for Elementor: 0 hasta 1.7.1058

Leer análisis →
Media

WordPress · Meta Field Block – Display custom fields in the Block Editor without coding

CVE-2026-6252: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Meta Field Block – Display custom fields in the Block Editor without coding

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Meta Field Block – Display custom fields in the Block Editor without coding. Meta Field Block – Display custom fields in the Block Editor without coding: 0 hasta 1.5.2

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-6225: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.6

Leer análisis →
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-6145: CWE-862: Falta de autorización en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.5

Leer análisis →
Alta

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5396: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.1.21

Leer análisis →
Alta

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5395: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.2.0

Leer análisis →
Media

WordPress · Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

CVE-2026-5361: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More. Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More: 0 hasta 1.12.4

Leer análisis →
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-5243: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.11

Leer análisis →
Media

WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-5193: CWE-269: Gestión incorrecta de privilegios en Essential Addons for Elementor – Popular Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.5.13

Leer análisis →
Media

WordPress · WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan

CVE-2026-3829: CWE-862: Falta de autorización en WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan. WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan: 0 hasta 7.8.5.10

Leer análisis →
Media

WordPress · Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More

CVE-2026-7619: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More. Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More: 0 hasta 1.8.10.4

Leer análisis →
Media

WordPress · Cost of Goods: Product Cost & Profit Calculator for WooCommerce

CVE-2026-6962: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Cost of Goods: Product Cost & Profit Calculator for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Cost of Goods: Product Cost & Profit Calculator for WooCommerce. Cost of Goods: Product Cost & Profit Calculator for WooCommerce: 0 hasta 4.1.0

Leer análisis →
Alta

WordPress · JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-6929: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en JoomSport – for Sports: Team & League, Football, Hockey & more

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en JoomSport – for Sports: Team & League, Football, Hockey & more. JoomSport – for Sports: Team & League, Football, Hockey & more: 0 hasta 5.7.7

Leer análisis →
Media

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-6828: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.2.1

Leer análisis →
Alta

WordPress · Custom Twitter Feeds – A Tweets Widget or X Feed Widget

CVE-2026-6177: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Custom Twitter Feeds – A Tweets Widget or X Feed Widget

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Custom Twitter Feeds – A Tweets Widget or X Feed Widget. Custom Twitter Feeds – A Tweets Widget or X Feed Widget: 0 hasta 2.5.4

Leer análisis →
Media

WordPress · ProfileGrid – User Profiles, Groups and Communities

CVE-2026-4608: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ProfileGrid – User Profiles, Groups and Communities

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ProfileGrid – User Profiles, Groups and Communities. ProfileGrid – User Profiles, Groups and Communities: 0 hasta 5.9.8.4

Leer análisis →