Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 50 de 70

Alta

WordPress · Login as User – Switch User & WooCommerce Login as Customer

CVE-2026-5617: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Login as User – Switch User & WooCommerce Login as Customer

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Login as User – Switch User & WooCommerce Login as Customer. Login as User – Switch User & WooCommerce Login as Customer: 0 hasta 1.0.1

Leer análisis
Media

WordPress · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

CVE-2026-4949: CWE-862: Falta de autorización en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: 0 hasta 4.16.12

Leer análisis
Crítica

WordPress · Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

CVE-2026-4880: CWE-269: Gestión incorrecta de privilegios en Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale). Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale): 0 hasta 1.11.0

Leer análisis
Media

WordPress · Power Charts – Responsive Beautiful Charts & Graphs

CVE-2026-4011: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Power Charts – Responsive Beautiful Charts & Graphs

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Power Charts – Responsive Beautiful Charts & Graphs. Power Charts – Responsive Beautiful Charts & Graphs: 0 hasta 0.1.0

Leer análisis
Alta

WordPress · Accessibly – WordPress Website Accessibility

CVE-2026-3643: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Accessibly – WordPress Website Accessibility

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Accessibly – WordPress Website Accessibility. Accessibly – WordPress Website Accessibility: 0 hasta 3.0.3

Leer análisis
Alta

WordPress · Age Verification & Identity Verification by Token of Trust

CVE-2026-2834: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Age Verification & Identity Verification by Token of Trust

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Age Verification & Identity Verification by Token of Trust. Age Verification & Identity Verification by Token of Trust: 0 hasta 3.32.3

Leer análisis
Media

WordPress · WholeSale Products Dynamic Pricing Management WooCommerce

CVE-2026-4479: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WholeSale Products Dynamic Pricing Management WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WholeSale Products Dynamic Pricing Management WooCommerce. WholeSale Products Dynamic Pricing Management WooCommerce: 0 hasta 1.2

Leer análisis
Alta

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-4388: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.40

Leer análisis
Media

WordPress · Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

CVE-2026-4109: CWE-862: Falta de autorización en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered). Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered): 0 hasta 4.1.8

Leer análisis
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-4059: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.3.5

Leer análisis
Alta

WordPress · Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts

CVE-2026-3017: CWE-502: Deserialización de datos no confiables en Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts

El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts. Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts: 0 hasta 3.0.12

Leer análisis
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-6203: CWE-601: vulnerabilidad de seguridad en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-601: vulnerabilidad de seguridad» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.4

Leer análisis
Media

WordPress · Optimole – Optimize Images in Real Time

CVE-2026-5226: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Optimole – Optimize Images in Real Time

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Optimole – Optimize Images in Real Time. Optimole – Optimize Images in Real Time: 0 hasta 4.2.3

Leer análisis
Alta

WordPress · Optimole – Optimize Images in Real Time

CVE-2026-5217: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Optimole – Optimize Images in Real Time

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Optimole – Optimize Images in Real Time. Optimole – Optimize Images in Real Time: 0 hasta 4.2.2

Leer análisis
Media

WordPress · LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes

CVE-2026-5207: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes. LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes: 0 hasta 9.2.1

Leer análisis
Media

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-4979: CWE-918: vulnerabilidad de seguridad en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.58

Leer análisis
Media

WordPress · Greenshift – animation and page builder blocks

CVE-2026-4895: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Greenshift – animation and page builder blocks

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Greenshift – animation and page builder blocks. Greenshift – animation and page builder blocks: 0 hasta 12.8.9

Leer análisis
Media

WordPress · BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library

CVE-2026-3498: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library. BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library: 0 hasta 2.2.15

Leer análisis
Media

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-4977: CWE-862: Falta de autorización en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.58

Leer análisis
Media

WordPress · Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely

CVE-2026-4305: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely. Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely: 0 hasta 1.0.16

Leer análisis
Media

WordPress · WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance

CVE-2026-2712: CWE-863: vulnerabilidad de seguridad en WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance

El registro oficial identifica la vulnerabilidad «CWE-863: vulnerabilidad de seguridad» en WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance. WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance: 0 hasta 4.5.0

Leer análisis
Media

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-5742: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.60

Leer análisis
Media

WordPress · MStore API – Create Native Android & iOS Apps On The Cloud

CVE-2026-3568: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en MStore API – Create Native Android & iOS Apps On The Cloud

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en MStore API – Create Native Android & iOS Apps On The Cloud. MStore API – Create Native Android & iOS Apps On The Cloud: 0 hasta 4.18.3

Leer análisis
Crítica

WordPress · Smart Slider 3 Pro for WordPress / Smart Slider 3 Pro for Joomla

CVE-2026-34424: Vulnerabilidad de seguridad en Smart Slider 3 Pro for WordPress / Smart Slider 3 Pro for Joomla

El registro oficial identifica la vulnerabilidad «Vulnerabilidad de seguridad» en Smart Slider 3 Pro for WordPress / Smart Slider 3 Pro for Joomla. Smart Slider 3 Pro for WordPress: 3.5.1.35, 0 hasta 3.5.1.34, 3.5.1.36; Smart Slider 3 Pro for Joomla: 3.5.1.35, 0 hasta 3.5.1.34, 3.5.1.36

Leer análisis
Media

WordPress · Masteriyo LMS – Online Course Builder for eLearning, LMS & Education

CVE-2026-5167: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Masteriyo LMS – Online Course Builder for eLearning, LMS & Education

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Masteriyo LMS – Online Course Builder for eLearning, LMS & Education. Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: 0 hasta 2.1.7

Leer análisis
Media

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-4785: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.3.0

Leer análisis
Media

WordPress · Element Pack – Widgets, Templates & Addons for Elementor

CVE-2026-4655: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Element Pack – Widgets, Templates & Addons for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Element Pack – Widgets, Templates & Addons for Elementor. Element Pack – Widgets, Templates & Addons for Elementor: 0 hasta 8.4.2

Leer análisis
Media

WordPress · Awesome Support – WordPress HelpDesk & Support Plugin

CVE-2026-4654: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Awesome Support – WordPress HelpDesk & Support Plugin

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Awesome Support – WordPress HelpDesk & Support Plugin. Awesome Support – WordPress HelpDesk & Support Plugin: 0 hasta 6.3.7

Leer análisis
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-4333: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.3.3

Leer análisis