Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 31 de 70

Media

WordPress · GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference

CVE-2026-6440: CWE-352: vulnerabilidad de seguridad en GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference. GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference: 0 hasta 1.1.8

Leer análisis
Media

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5069: CWE-863: vulnerabilidad de seguridad en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-863: vulnerabilidad de seguridad» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.2.1

Leer análisis
Media

WordPress · ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-15302: CWE-36: Absolute Path Traversal en ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

El registro oficial identifica la vulnerabilidad «CWE-36: Absolute Path Traversal» en ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup. ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: 0 hasta 4.0.27

Leer análisis
Media

WordPress · Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates

CVE-2026-15299: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates. Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates: 0 hasta 2.6.3

Leer análisis
Alta

WordPress · TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

CVE-2026-15298: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot. TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot: 0 hasta 1.14.14

Leer análisis
Media

WordPress · Brevo – Email, SMS, Web Push, Chat, and more.

CVE-2026-15297: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Brevo – Email, SMS, Web Push, Chat, and more.

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Brevo – Email, SMS, Web Push, Chat, and more.. Brevo – Email, SMS, Web Push, Chat, and more.: 0 hasta 3.1.77

Leer análisis
Media

WordPress · affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

CVE-2026-15296: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display. affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display: 0 hasta 3.7.0

Leer análisis
Alta

WordPress · ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

CVE-2026-15291: CWE-862: Falta de autorización en ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form. ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form: 0 hasta 3.1.3

Leer análisis
Alta

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-15290: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.10.1

Leer análisis
Alta

WordPress · SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

CVE-2026-15288: CWE-20: vulnerabilidad de seguridad en SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator. SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator: 0 hasta 2.2.1

Leer análisis
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-15285: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.11

Leer análisis
Media

WordPress · King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

CVE-2026-15284: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder. King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder: 0 hasta 51.1.62

Leer análisis
Media

WordPress · BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

CVE-2026-15104: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot. BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot: 0 hasta 4.6.0

Leer análisis
Media

WordPress · Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

CVE-2026-14475: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: 0 hasta 4.3.6

Leer análisis
Media

WordPress · Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

CVE-2026-13710: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress. Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress: 0 hasta 3.2.6

Leer análisis
Media

WordPress · Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase

CVE-2026-13247: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase. Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase: 0 hasta 5.5

Leer análisis
Media

WordPress · Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

CVE-2026-13039: CWE-862: Falta de autorización en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered). Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered): 4.0.26 hasta 4.1.15

Leer análisis
Media

WordPress · JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-13010: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en JoomSport – for Sports: Team & League, Football, Hockey & more

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en JoomSport – for Sports: Team & League, Football, Hockey & more. JoomSport – for Sports: Team & League, Football, Hockey & more: 0 hasta 5.7.9

Leer análisis
Media

WordPress · Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

CVE-2026-12924: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered). Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered): 0 hasta 4.1.15

Leer análisis
Media

WordPress · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-12918: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 1.24.1

Leer análisis
Crítica

WordPress · miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)

CVE-2026-12761: CWE-287: Autenticación incorrecta en miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn). miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn): 0 hasta 7.7.0

Leer análisis
Alta

WordPress · WP Cost Estimation & Payment Forms Builder

CVE-2026-9253: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Cost Estimation & Payment Forms Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Cost Estimation & Payment Forms Builder. WP Cost Estimation & Payment Forms Builder: 0 hasta 10.5.97; WP Cost Estimation & Payment Forms Builder: 0 hasta 10.5.97

Leer análisis
Alta

WordPress · Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

CVE-2026-8848: CWE-862: Falta de autorización en Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder. Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder: 0 hasta 1.22.0

Leer análisis
Media

WordPress · Bookero.pl – system rezerwacji online

CVE-2026-6910: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Bookero.pl – system rezerwacji online

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Bookero.pl – system rezerwacji online. Bookero.pl – system rezerwacji online: 0 hasta 2.2

Leer análisis
Alta

WordPress · Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder

CVE-2026-14372: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder. Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder: 0 hasta 3.1.1

Leer análisis
Media

WordPress · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-14342: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 1.24.2

Leer análisis
Alta

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-13492: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.65

Leer análisis
Media

WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

CVE-2026-13450: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.4

Leer análisis
Alta

WordPress · EventPrime – Events Calendar, Bookings and Tickets

CVE-2026-13441: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en EventPrime – Events Calendar, Bookings and Tickets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en EventPrime – Events Calendar, Bookings and Tickets. EventPrime – Events Calendar, Bookings and Tickets: 0 hasta 4.3.4.2

Leer análisis
Media

WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-13080: CWE-98: vulnerabilidad de seguridad en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

El registro oficial identifica la vulnerabilidad «CWE-98: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7

Leer análisis
Media

WordPress · ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

CVE-2026-13011: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce. ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce: 0 hasta 1.17.5

Leer análisis
Media

WordPress · Hydra Booking — Appointment Scheduling & Booking Calendar

CVE-2026-12433: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Hydra Booking — Appointment Scheduling & Booking Calendar

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Hydra Booking — Appointment Scheduling & Booking Calendar. Hydra Booking — Appointment Scheduling & Booking Calendar: 0 hasta 1.2.1

Leer análisis
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12418: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7

Leer análisis
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-12406: CWE-862: Falta de autorización en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7

Leer análisis
Media

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-12170: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 10.10.2

Leer análisis