Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 12 de 70

Media

WordPress · WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses

CVE-2026-10630: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses. WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses: 0 hasta 3.2.29

Leer análisis
Alta

WordPress · Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads

CVE-2026-78268: CWE-497: vulnerabilidad de seguridad en Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads

El registro oficial identifica la vulnerabilidad «CWE-497: vulnerabilidad de seguridad» en Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads. Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads: n/a hasta 1.2.0

Leer análisis
Alta

WordPress · ShopBuilder Pro – Elementor WooCommerce Builder Addons

CVE-2026-32477: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en ShopBuilder Pro – Elementor WooCommerce Builder Addons

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en ShopBuilder Pro – Elementor WooCommerce Builder Addons. ShopBuilder Pro – Elementor WooCommerce Builder Addons: n/a hasta 2.2.0

Leer análisis
Alta

WordPress · Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More

CVE-2026-28153: CWE-862: Falta de autorización en Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More. Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More: n/a hasta 1.7.1

Leer análisis
Media

WordPress · AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

CVE-2026-76074: CWE-862: Falta de autorización en AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress. AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress: 0 hasta 5.8.4

Leer análisis
Media

WordPress · AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

CVE-2026-76057: CWE-862: Falta de autorización en AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress. AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress: 0 hasta 5.8.4

Leer análisis
Media

WordPress · WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

CVE-2026-18027: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels. WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels: 0 hasta 4.9.8

Leer análisis
Crítica

WordPress · Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code

CVE-2026-77264: CWE-640: vulnerabilidad de seguridad en Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code

El registro oficial identifica la vulnerabilidad «CWE-640: vulnerabilidad de seguridad» en Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code. Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code: 0 hasta 4.8.6

Leer análisis