Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 24 de 70

Alta

WordPress · Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

CVE-2026-12476: CWE-434: vulnerabilidad de seguridad en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy. Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 0 hasta 3.6.9

Leer análisis
Media

WordPress · SpeedyCache – Cache, Optimization, Performance

CVE-2026-5114: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en SpeedyCache – Cache, Optimization, Performance

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en SpeedyCache – Cache, Optimization, Performance. SpeedyCache – Cache, Optimization, Performance: 0 hasta 1.3.8

Leer análisis
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-16811: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5

Leer análisis
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-16797: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5

Leer análisis
Media

WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

CVE-2026-16773: CWE-200: Exposición de información sensible a un actor no autorizado en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.5.9

Leer análisis
Alta

WordPress · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

CVE-2026-16585: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots. Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots: 0 hasta 2.15.19

Leer análisis
Media

WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

CVE-2026-15730: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.9.1

Leer análisis
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15673: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15671: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis
Media

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15670: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis
Media

WordPress · Tutor LMS – eLearning and online course solution

CVE-2026-15444: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Tutor LMS – eLearning and online course solution

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 4.0.1

Leer análisis
Media

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-15411: CWE-862: Falta de autorización en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis
Media

WordPress · Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

CVE-2026-15393: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates. Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates: 0 hasta 2.2.11

Leer análisis
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-15267: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.9

Leer análisis
Media

WordPress · WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

CVE-2026-15136: CWE-352: vulnerabilidad de seguridad en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode. WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: 0 hasta 4.3.7

Leer análisis
Alta

WordPress · Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

CVE-2026-15025: CWE-862: Falta de autorización en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: 0 hasta 7.3.2

Leer análisis
Media

WordPress · Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

CVE-2026-15016: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions. Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: 0 hasta 3.8.1

Leer análisis
Crítica

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-15014: CWE-288: vulnerabilidad de seguridad en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-288: vulnerabilidad de seguridad» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7

Leer análisis
Alta

WordPress · Online Scheduling and Appointment Booking System – Bookly

CVE-2026-14516: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Online Scheduling and Appointment Booking System – Bookly

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Online Scheduling and Appointment Booking System – Bookly. Online Scheduling and Appointment Booking System – Bookly: 0 hasta 27.5

Leer análisis
Alta

WordPress · Demi – One Click Demo Import, Backup & Site Migration

CVE-2026-14490: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Demi – One Click Demo Import, Backup & Site Migration

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Demi – One Click Demo Import, Backup & Site Migration. Demi – One Click Demo Import, Backup & Site Migration: 0 hasta 0.0.7

Leer análisis
Alta

WordPress · Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

CVE-2026-14328: CWE-269: Gestión incorrecta de privilegios en Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress. Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress: 0 hasta 4.4.1

Leer análisis
Alta

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-13440: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis
Alta

WordPress · TrueBooker – Appointment Booking and Scheduler System

CVE-2026-13161: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en TrueBooker – Appointment Booking and Scheduler System

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en TrueBooker – Appointment Booking and Scheduler System. TrueBooker – Appointment Booking and Scheduler System: 0 hasta 1.2.2

Leer análisis
Media

WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

CVE-2026-13110: CWE-862: Falta de autorización en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0

Leer análisis
Alta

WordPress · Premium Packages – Sell Digital Products Securely

CVE-2026-12800: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Premium Packages – Sell Digital Products Securely

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Premium Packages – Sell Digital Products Securely. Premium Packages – Sell Digital Products Securely: 0 hasta 6.2.0

Leer análisis
Alta

WordPress · WP Fast Total Search – The Power of Indexed Search

CVE-2026-12741: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Fast Total Search – The Power of Indexed Search

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Fast Total Search – The Power of Indexed Search. WP Fast Total Search – The Power of Indexed Search: 0 hasta 1.80.280

Leer análisis
Media

WordPress · PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer

CVE-2026-12124: CWE-862: Falta de autorización en PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer. PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer: 0 hasta 1.1.0

Leer análisis
Media

WordPress · Checkout Field Editor for WooCommerce – Checkout Manager

CVE-2026-66475: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Checkout Field Editor for WooCommerce – Checkout Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Checkout Field Editor for WooCommerce – Checkout Manager. Checkout Field Editor for WooCommerce – Checkout Manager: n/a hasta 3.0.5

Leer análisis
Media

WordPress · Photonic Gallery & Lightbox for Flickr, SmugMug & Others

CVE-2026-66434: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Photonic Gallery & Lightbox for Flickr, SmugMug & Others

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Photonic Gallery & Lightbox for Flickr, SmugMug & Others. Photonic Gallery & Lightbox for Flickr, SmugMug & Others: n/a hasta 3.33

Leer análisis
Media

WordPress · Anti Spam and list cleaner – AcyChecker

CVE-2026-65448: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Anti Spam and list cleaner – AcyChecker

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Anti Spam and list cleaner – AcyChecker. Anti Spam and list cleaner – AcyChecker: n/a hasta 1.8.1

Leer análisis
Alta

WordPress · Spam protection, AntiSpam, FireWall by CleanTalk

CVE-2026-65437: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Spam protection, AntiSpam, FireWall by CleanTalk

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Spam protection, AntiSpam, FireWall by CleanTalk. Spam protection, AntiSpam, FireWall by CleanTalk: n/a hasta 6.82

Leer análisis
Media

WordPress · RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg

CVE-2026-59559: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg. RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg: n/a hasta 1.5.1

Leer análisis