Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 9 de 47

Media

WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

CVE-2026-13450: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.4

Leer análisis →
Alta

WordPress · EventPrime – Events Calendar, Bookings and Tickets

CVE-2026-13441: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en EventPrime – Events Calendar, Bookings and Tickets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en EventPrime – Events Calendar, Bookings and Tickets. EventPrime – Events Calendar, Bookings and Tickets: 0 hasta 4.3.4.2

Leer análisis →
Media

WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-13080: CWE-98: vulnerabilidad de seguridad en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

El registro oficial identifica la vulnerabilidad «CWE-98: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7

Leer análisis →
Media

WordPress · ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

CVE-2026-13011: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce. ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce: 0 hasta 1.17.5

Leer análisis →
Media

WordPress · Hydra Booking — Appointment Scheduling & Booking Calendar

CVE-2026-12433: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Hydra Booking — Appointment Scheduling & Booking Calendar

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Hydra Booking — Appointment Scheduling & Booking Calendar. Hydra Booking — Appointment Scheduling & Booking Calendar: 0 hasta 1.2.1

Leer análisis →
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12418: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7

Leer análisis →
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12406: CWE-862: Falta de autorización en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7

Leer análisis →
Media

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-12170: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 10.10.2

Leer análisis →
Media

WordPress · Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration

CVE-2026-11359: CWE-862: Falta de autorización en Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration. Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration: 0 hasta 3.4

Leer análisis →
Alta

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-6820: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.8

Leer análisis →
Alta

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-6818: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.8

Leer análisis →
Media

WordPress · Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

CVE-2026-6740: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder. Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder: 0 hasta 4.7.4

Leer análisis →
Media

WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-6459: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Essential Addons for Elementor – Popular Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.6.2

Leer análisis →
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-5459: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.1

Leer análisis →
Alta

WordPress · WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

CVE-2026-3688: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WCFM Membership – WooCommerce Memberships for Multivendor Marketplace. WCFM Membership – WooCommerce Memberships for Multivendor Marketplace: 0 hasta 2.11.10

Leer análisis →
Media

WordPress · Recurio – Ultimate Subscription for WooCommerce

CVE-2026-12936: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Recurio – Ultimate Subscription for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Recurio – Ultimate Subscription for WooCommerce. Recurio – Ultimate Subscription for WooCommerce: 0 hasta 1.1.3

Leer análisis →
Media

WordPress · Chatra Live Chat + ChatBot + Cart Saver

CVE-2026-12041: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Chatra Live Chat + ChatBot + Cart Saver

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Chatra Live Chat + ChatBot + Cart Saver. Chatra Live Chat + ChatBot + Cart Saver: 0 hasta 1.0.12

Leer análisis →
Media

WordPress · Social Share, Social Login and Social Comments Plugin – Super Socializer

CVE-2026-11798: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Social Share, Social Login and Social Comments Plugin – Super Socializer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Social Share, Social Login and Social Comments Plugin – Super Socializer. Social Share, Social Login and Social Comments Plugin – Super Socializer: 0 hasta 7.14.5

Leer análisis →
Crítica

WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-14345: CWE-434: vulnerabilidad de seguridad en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7

Leer análisis →
Crítica

WordPress · FileOrganizer / Advanced File Manager / File Manager Pro

CVE-2026-6382: CWE-94: Control incorrecto de la generación de código (Code Injection) en FileOrganizer / Advanced File Manager / File Manager Pro

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en FileOrganizer / Advanced File Manager / File Manager Pro. FileOrganizer: 0 hasta 1.1.9; Advanced File Manager: 0 hasta 5.4.12; File Manager Pro: 0 hasta 2.1.1; File Manager: 0 hasta 8.0.4

Leer análisis →
Media

WordPress · Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations

CVE-2026-12154: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations. Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations: 0 hasta 2.7.3

Leer análisis →
Crítica

WordPress · Printcart Web to Print Product Designer for WooCommerce

CVE-2026-9725: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Printcart Web to Print Product Designer for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Printcart Web to Print Product Designer for WooCommerce. Printcart Web to Print Product Designer for WooCommerce: 0 hasta 2.5.2

Leer análisis →
Media

WordPress · CM Business Directory – Optimise and showcase local business

CVE-2026-8892: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CM Business Directory – Optimise and showcase local business

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CM Business Directory – Optimise and showcase local business. CM Business Directory – Optimise and showcase local business: 0 hasta 1.5.7

Leer análisis →
Media

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-8489: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.11.4

Leer análisis →
Alta

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-13040: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.2.2

Leer análisis →
Media

WordPress · Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

CVE-2026-12920: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: 0 hasta 4.3.5

Leer análisis →
Media

WordPress · weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

CVE-2026-12734: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot. weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: 0 hasta 2.3.0

Leer análisis →
Media

WordPress · weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

CVE-2026-12731: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot. weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: 0 hasta 2.3.0

Leer análisis →
Media

WordPress · CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x

CVE-2026-11778: CWE-94: Control incorrecto de la generación de código (Code Injection) en CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x. CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x: 0 hasta 2.2.14

Leer análisis →
Media

WordPress · Appointment Bookings for Zoom GoogleMeet and more – Wappointment

CVE-2026-9188: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Appointment Bookings for Zoom GoogleMeet and more – Wappointment

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Appointment Bookings for Zoom GoogleMeet and more – Wappointment. Appointment Bookings for Zoom GoogleMeet and more – Wappointment: 0 hasta 2.7.6

Leer análisis →
Media

WordPress · Database for Contact Form 7, WPforms, Elementor forms

CVE-2026-9145: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Database for Contact Form 7, WPforms, Elementor forms

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Database for Contact Form 7, WPforms, Elementor forms. Database for Contact Form 7, WPforms, Elementor forms: 0 hasta 1.5.1

Leer análisis →