Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 36 de 70

Alta

WordPress · Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups

CVE-2026-54839: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups. Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups: n/a hasta 2.0.9

Leer análisis
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1869: CWE-862: Falta de autorización en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.2.0

Leer análisis
Media

WordPress · Groundhogg — CRM, Newsletters, and Marketing Automation

CVE-2026-13226: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Groundhogg — CRM, Newsletters, and Marketing Automation

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Groundhogg — CRM, Newsletters, and Marketing Automation. Groundhogg — CRM, Newsletters, and Marketing Automation: 0 hasta 4.5.4

Leer análisis
Alta

WordPress · Advanced Order Export For WooCommerce

CVE-2026-56042: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Advanced Order Export For WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Advanced Order Export For WooCommerce. Advanced Order Export For WooCommerce: n/a hasta 4.0.9

Leer análisis
Sin clasificar

WordPress · Linux

CVE-2026-53155: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 65edfda6f3f2e58f757485a056e4f1775a1404a8 hasta d7251c8d3f7cea76543abac6cf4ed15582c10846, 65edfda6f3f2e58f757485a056e4f1775a1404a8 hasta 43e7f189769c512c843184a8a5892ac779a6bd90; Linux: 6.19, 0 hasta 6.19, 7.0.13 hasta 7.0.*, 7.1 hasta *

Leer análisis
Alta

WordPress · Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

CVE-2026-12937: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin. Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin: 0 hasta 2.22.7

Leer análisis
Media

WordPress · Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

CVE-2026-10833: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns. Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns: 0 hasta 6.1.4

Leer análisis
Media

WordPress · Avalon23 Products Filter for WooCommerce

CVE-2026-8865: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Avalon23 Products Filter for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Avalon23 Products Filter for WooCommerce. Avalon23 Products Filter for WooCommerce: 0 hasta 1.1.6

Leer análisis
Alta

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-7761: CWE-862: Falta de autorización en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.11.4

Leer análisis
Sin clasificar

WordPress · Linux

CVE-2026-53038: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta 081b557cb56e1cfa8d1619b2601b01c53e3f418c, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta b6766b171a5c4c33b26ff6fec530cb798db1f75e, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta 88d4e89a39f0de07798ca3fd93bd1a9ea212a82e, 9fa8e76250082a45d0d3dad525419ab98bd01658 hasta d7bd8cf0b348d3edae7bee33e74a32b21668b181; Linux: 6.10, 0 hasta 6.10, 6.12.91 hasta 6.12.*, 6.18.33 hasta 6.18.*, 7.0.10 hasta 7.0.*, 7.1 hasta *

Leer análisis
Media

WordPress · Xpro Addons — 140+ Widgets for Elementor

CVE-2026-11614: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Xpro Addons — 140+ Widgets for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Xpro Addons — 140+ Widgets for Elementor. Xpro Addons — 140+ Widgets for Elementor: 0 hasta 1.7.2

Leer análisis