Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 32 de 70

Media

WordPress · Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration

CVE-2026-11359: CWE-862: Falta de autorización en Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration. Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration: 0 hasta 3.4

Leer análisis
Media

WordPress · Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

CVE-2026-6740: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder. Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder: 0 hasta 4.7.4

Leer análisis
Media

WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-6459: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Essential Addons for Elementor – Popular Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.6.2

Leer análisis
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-5459: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.1

Leer análisis
Alta

WordPress · WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

CVE-2026-3688: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WCFM Membership – WooCommerce Memberships for Multivendor Marketplace. WCFM Membership – WooCommerce Memberships for Multivendor Marketplace: 0 hasta 2.11.10

Leer análisis
Media

WordPress · Recurio – Ultimate Subscription for WooCommerce

CVE-2026-12936: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Recurio – Ultimate Subscription for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Recurio – Ultimate Subscription for WooCommerce. Recurio – Ultimate Subscription for WooCommerce: 0 hasta 1.1.3

Leer análisis
Media

WordPress · Chatra Live Chat + ChatBot + Cart Saver

CVE-2026-12041: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Chatra Live Chat + ChatBot + Cart Saver

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Chatra Live Chat + ChatBot + Cart Saver. Chatra Live Chat + ChatBot + Cart Saver: 0 hasta 1.0.12

Leer análisis
Media

WordPress · Social Share, Social Login and Social Comments Plugin – Super Socializer

CVE-2026-11798: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Social Share, Social Login and Social Comments Plugin – Super Socializer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Social Share, Social Login and Social Comments Plugin – Super Socializer. Social Share, Social Login and Social Comments Plugin – Super Socializer: 0 hasta 7.14.5

Leer análisis
Crítica

WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-14345: CWE-434: vulnerabilidad de seguridad en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7

Leer análisis
Crítica

WordPress · FileOrganizer / Advanced File Manager / File Manager Pro

CVE-2026-6382: CWE-94: Control incorrecto de la generación de código (Code Injection) en FileOrganizer / Advanced File Manager / File Manager Pro

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en FileOrganizer / Advanced File Manager / File Manager Pro. FileOrganizer: 0 hasta 1.1.9; Advanced File Manager: 0 hasta 5.4.12; File Manager Pro: 0 hasta 2.1.1; File Manager: 0 hasta 8.0.4

Leer análisis
Media

WordPress · Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations

CVE-2026-12154: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations. Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations: 0 hasta 2.7.3

Leer análisis
Crítica

WordPress · Printcart Web to Print Product Designer for WooCommerce

CVE-2026-9725: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Printcart Web to Print Product Designer for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Printcart Web to Print Product Designer for WooCommerce. Printcart Web to Print Product Designer for WooCommerce: 0 hasta 2.5.2

Leer análisis
Media

WordPress · CM Business Directory – Optimise and showcase local business

CVE-2026-8892: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CM Business Directory – Optimise and showcase local business

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CM Business Directory – Optimise and showcase local business. CM Business Directory – Optimise and showcase local business: 0 hasta 1.5.7

Leer análisis
Media

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-8489: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.11.4

Leer análisis
Alta

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-13040: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.2.2

Leer análisis
Media

WordPress · Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

CVE-2026-12920: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: 0 hasta 4.3.5

Leer análisis
Media

WordPress · weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

CVE-2026-12734: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot. weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: 0 hasta 2.3.0

Leer análisis
Media

WordPress · weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

CVE-2026-12731: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot. weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: 0 hasta 2.3.0

Leer análisis
Media

WordPress · CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x

CVE-2026-11778: CWE-94: Control incorrecto de la generación de código (Code Injection) en CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x. CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x: 0 hasta 2.2.14

Leer análisis
Media

WordPress · Appointment Bookings for Zoom GoogleMeet and more – Wappointment

CVE-2026-9188: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Appointment Bookings for Zoom GoogleMeet and more – Wappointment

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Appointment Bookings for Zoom GoogleMeet and more – Wappointment. Appointment Bookings for Zoom GoogleMeet and more – Wappointment: 0 hasta 2.7.6

Leer análisis
Media

WordPress · Database for Contact Form 7, WPforms, Elementor forms

CVE-2026-9145: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Database for Contact Form 7, WPforms, Elementor forms

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Database for Contact Form 7, WPforms, Elementor forms. Database for Contact Form 7, WPforms, Elementor forms: 0 hasta 1.5.1

Leer análisis
Media

WordPress · Surbma | Yoast SEO Breadcrumb Shortcode

CVE-2026-57764: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Surbma | Yoast SEO Breadcrumb Shortcode

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Surbma | Yoast SEO Breadcrumb Shortcode. Surbma | Yoast SEO Breadcrumb Shortcode: n/a hasta 1.2

Leer análisis
Media

WordPress · Mosaic Gallery – Advanced Gallery

CVE-2026-57755: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Mosaic Gallery – Advanced Gallery

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Mosaic Gallery – Advanced Gallery. Mosaic Gallery – Advanced Gallery: n/a hasta 1.2.0

Leer análisis
Media

WordPress · Livemesh Addons for WPBakery Page Builder

CVE-2026-57754: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Livemesh Addons for WPBakery Page Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Livemesh Addons for WPBakery Page Builder. Livemesh Addons for WPBakery Page Builder: n/a hasta 3.9.4

Leer análisis