Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 37 de 47

Alta

WordPress · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

CVE-2026-3453: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: 0 hasta 4.16.11

Leer análisis →
Alta

WordPress · Checkout Field Editor (Checkout Manager) for WooCommerce

CVE-2026-3231: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Checkout Field Editor (Checkout Manager) for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Checkout Field Editor (Checkout Manager) for WooCommerce. Checkout Field Editor (Checkout Manager) for WooCommerce: 0 hasta 2.1.7

Leer análisis →
Alta

WordPress · WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters

CVE-2026-3222: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters. WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters: 0 hasta 4.9.1

Leer análisis →
Media

WordPress · weForms – Easy Drag & Drop Contact Form Builder For WordPress

CVE-2026-2707: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en weForms – Easy Drag & Drop Contact Form Builder For WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en weForms – Easy Drag & Drop Contact Form Builder For WordPress. weForms – Easy Drag & Drop Contact Form Builder For WordPress: 0 hasta 1.6.27

Leer análisis →
Media

WordPress · WP ULike – Like & Dislike Buttons for Engagement and Feedback

CVE-2026-2358: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP ULike – Like & Dislike Buttons for Engagement and Feedback

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP ULike – Like & Dislike Buttons for Engagement and Feedback. WP ULike – Like & Dislike Buttons for Engagement and Feedback: 0 hasta 5.0.1

Leer análisis →
Alta

WordPress · ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)

CVE-2026-1993: CWE-269: Gestión incorrecta de privilegios en ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin). ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin): 7.1.0 hasta 9.0.2

Leer análisis →
Alta

WordPress · ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)

CVE-2026-1992: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin). ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin): 8.0.0 hasta 9.0.2

Leer análisis →
Alta

WordPress · Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-1708: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: 0 hasta 1.6.9.27

Leer análisis →
Media

WordPress · NextScripts: Social Networks Auto-Poster

CVE-2026-3228: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en NextScripts: Social Networks Auto-Poster

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en NextScripts: Social Networks Auto-Poster. NextScripts: Social Networks Auto-Poster: 0 hasta 4.4.6

Leer análisis →
Media

WordPress · Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer

CVE-2026-2569: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer. Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer: 0 hasta 2.4.20

Leer análisis →
Media

WordPress · RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

CVE-2026-2433: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging. RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging: 0 hasta 5.0.11

Leer análisis →
Media

WordPress · CM Custom Reports – Flexible reporting to track what matters most

CVE-2026-2431: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CM Custom Reports – Flexible reporting to track what matters most

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CM Custom Reports – Flexible reporting to track what matters most. CM Custom Reports – Flexible reporting to track what matters most: 0 hasta 1.2.7

Leer análisis →
Media

WordPress · WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

CVE-2026-2830: CWE-94: Control incorrecto de la generación de código (Code Injection) en WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets. WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets: 0 hasta 4.0.0

Leer análisis →
Crítica

WordPress · WP Attractive Donations System - Easy Stripe & Paypal donations

CVE-2026-28115: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Attractive Donations System - Easy Stripe & Paypal donations

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Attractive Donations System - Easy Stripe & Paypal donations. WP Attractive Donations System - Easy Stripe & Paypal donations: 0 hasta 1.25

Leer análisis →
Alta

WordPress · LambertGroup - AllInOne - Banner with Playlist

CVE-2026-28110: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LambertGroup - AllInOne - Banner with Playlist

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LambertGroup - AllInOne - Banner with Playlist. LambertGroup - AllInOne - Banner with Playlist: 0 hasta 3.8

Leer análisis →
Alta

WordPress · LambertGroup - AllInOne - Banner with Thumbnails

CVE-2026-28108: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LambertGroup - AllInOne - Banner with Thumbnails

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LambertGroup - AllInOne - Banner with Thumbnails. LambertGroup - AllInOne - Banner with Thumbnails: 0 hasta 3.8

Leer análisis →