Wordfence: previene ataques con el informe semanal de vulnerabilidades WP
Este es un resumen del artículo. Si necesitas contexto adicional, aquí tienes el enlace original: https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/


Triple Threat Bug Bounty Challenge 


Hunt High Threat vulnerabilities and earn triple the incentives!
Now through April 6, 2026, earn three stacked bonuses on all valid submissions from our ‘High Threat Vulnerabilities’ list:
2x all high threat vulnerability bounties (excluding 5,000,000+ installs)
+30% bonus for high threat vulnerabilities in software with 30,000+ active installs (excluding 5,000,000+ installs)
$300 extra for every 3 High Threat vulnerabilities submitted (minimum of 1,000 installs)
Use the Bounty Estimator to see what rewards are possible through the promotion.
Submit through our Bug Bounty Program today to maximize your impact and your payout.
Last week, there were 201 vulnerabilities disclosed in 84 WordPress Plugins and 107 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 60 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
-
-
- Master Addons for Elementor Premium <= 2.1.3 – Authenticated (Subscriber+) Remote Code Execution via render_preview
- Woocommerce Wholesale Lead Capture <= 2.0.3.1 – Unauthenticated Privilege Escalation
- Woocommerce Wholesale Lead Capture <= 2.0.3.1 – Unauthenticated Arbitrary File Upload
- WAF-RULE-896 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-897 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-901 – Data redacted while we work with the vendor on a patch.
-
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
| Patch Status | Number of Vulnerabilities |
|---|---|
| Patched | 72 |
| Unpatched | 129 |
Total Vulnerabilities by CVSS Severity Last Week
| Severity Rating | Number of Vulnerabilities |
|---|---|
| Medium Severity | 70 |
| High Severity | 124 |
| Critical Severity | 7 |
Total Vulnerabilities by CWE Type Last Week
| Vulnerability Type by CWE | Number of Vulnerabilities |
|---|---|
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | 81 |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 38 |
| Deserialization of Untrusted Data | 21 |
| Missing Authorization | 16 |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 10 |
| Exposure of Sensitive Information to an Unauthorized Actor | 6 |
| Unrestricted Upload of File with Dangerous Type | 6 |
| Cross-Site Request Forgery (CSRF) | 5 |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 5 |
| Improper Control of Generation of Code ('Code Injection') | 4 |
| Improper Privilege Management | 4 |
| Server-Side Request Forgery (SSRF) | 2 |
| Authentication Bypass Using an Alternate Path or Channel | 1 |
| Authorization Bypass Through User-Controlled Key | 1 |
| Incorrect Privilege Assignment | 1 |
Researchers That Contributed to WordPress Security Last Week
| Researcher Name | Number of Vulnerabilities |
|---|---|
| 79 | |
| 25 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| AI ChatBot with ChatGPT and Content Generator by AYS | ays-chatgpt-assistant |
| All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login | login-with-azure |
| All-in-One Video Gallery | all-in-one-video-gallery |
| Apocalypse Meow | apocalypse-meow |
| Booking for Appointments and Events Calendar – Amelia | ameliabooking |
| Bus Ticket Booking with Seat Reservation | bus-ticket-booking-with-seat-reservation |
| Carta Online | carta-online |
| CM Custom Reports – Flexible reporting to track what matters most | cm-custom-reports |
| Community Events | community-events |
| Consensus Embed | consensus-embed |
| Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | contest-gallery |
| DA Media GigList | damedia-giglist |
| Database for Contact Form 7, WPforms, Elementor forms | contact-form-entries |
| Drag and Drop Multiple File Upload for Contact Form 7 | drag-and-drop-multiple-file-upload-contact-form-7 |
| Easy PHP Settings | easy-php-settings |
| Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress | easy-post-submission |
| Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | email-subscribers |
| Enable Media Replace | enable-media-replace |
| Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More | envira-gallery-lite |
| EventON (Pro) – WordPress Virtual Event Calendar Plugin | eventON |
| Fast Page & Post Duplicator | page-or-post-clone |
| Fluent Forms Pro Add On Pack | fluentformpro |
| Font Pairing Preview For Landing Pages | wp-font-pairing-preview |
| FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More | formgent |
| Greenshift – animation and page builder blocks | greenshift-animation-and-page-builder-blocks |
| Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | gutena-forms |
| Hammas Calendar | hammas-calendar |
| HUMN-1 AI Website Scanner & Human Certification by Winston AI | winston-ai-wp |
| Infomaniak Connect for OpenID | infomaniak-connect-openid |
| ionCube Tester Plus | ioncube-tester-plus |
| JS Archive List | jquery-archive-list-widget |
| JS Help Desk – AI-Powered Support & Ticketing System | js-support-ticket |
| LatePoint – Calendar Booking Plugin for Appointments and Events | latepoint |
| Lisfinity Core – Lisfinity Core plugin used for pebas® Lisfinity WordPress theme | lisfinity-core |
| LMS Elementor Pro | lms-elementor-pro |
| LotekMedia Popup Form | ltm-popup-form |
| Mail Mint – Newsletters, Email Marketing, Automation, WooCommerce Emails, Post Notification, and more | mail-mint |
| MailArchiver | mailarchiver |
| Master Addons for Elementor Premium | master-addons-pro |
| MDJM Event Management | mobile-dj-manager |
| Media Library Alt Text Editor | media-library-alt-text-editor |
| Media Library Assistant | media-library-assistant |
| Membership Plugin – Restrict Content | restrict-content |
| Meta Box | meta-box |
| Morkva UA Shipping | morkva-ua-shipping |
| My Album Gallery | my-album-gallery |
| My auctions allegro | my-auctions-allegro-free-edition |
| My Calendar – Accessible Event Manager | my-calendar |
| MyQtip – easy qTip2 | myqtip-easy-qtip2 |
| OoohBoi Steroids for Elementor | ooohboi-steroids-for-elementor |
| Page Builder by SiteOrigin | siteorigin-panels |
| Paid Videochat Turnkey Site – HTML5 PPV Live Webcams | ppv-live-webcams |
| Pixfort Core | pixfort-core |
| Podlove Web Player | podlove-web-player |
| Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | ultimate-post |
| ProfileGrid – User Profiles, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
| Purchase Button For Affiliate Link | purchase-button |
| RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | wp-rss-aggregator |
| Secudeal Payments for Ecommerce | secudeal-payments-for-ecommerce |
| Seraphinite Accelerator | seraphinite-accelerator |
| Show YouTube video | show-youtube-video |
| Stock Ticker | stock-ticker |
| Subscription for WooCommerce – WordPress Recurring Payments Plugin | subscription |
| Super Stage WP | super-stage-wp |
| Taskbuilder – Project Management & Task Management Tool With Kanban Board | taskbuilder |
| True Ranker | seo-local-rank |
| Ultimate Addons for WPBakery | Ultimate_VC_Addons |
| Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | uncanny-automator |
| User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | user-registration |
| WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More | webtoffee-product-feed |
| Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets | widget-options |
| WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | optin |
| WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets | wp-all-import |
| WP App Bar | wp-app-bar |
| WP Booking System – Booking Calendar | wp-booking-system |
| WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales | easy-sticky-sidebar |
| Wp EMember | wp-eMember |
| WP Frontend Profile | wp-front-end-profile |
| WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | cf7-zendesk |
| WP-Members Membership Plugin | wp-members |
| WPBookit | wpbookit |
| wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | wpdatatables |
| Wueen | wueen |
| ZIP Code Based Content Protection | zip-code-based-content-protection |
WordPress Themes with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme | window-ac-services |
| Agrofood – Elementor WooCommerce WordPress Theme | agrofood |
| Aldo | aldo |
| Amoli – Fashion Photography WordPress Theme | amoli |
| Askka – Candle Shop WordPress Theme | askka |
| Au Pair Agency – Babysitting & Nanny Theme | au-pair-agency |
| Avventure | avventure |
| Berger – WordPress Creative Agency Portfolio Theme | berger |
| Blocksy | blocksy |
| Bonbon | bonbon |
| BuddyApp – Mobile First Community WordPress theme | buddyapp |
| CarZone – A Complete Car Dealer HTML Wire-Frame | carzone |
| CasaMia | Property Rental Real Estate WordPress Theme | casamia |
| Charety – Charity & Donation WordPress Theme | charety |
| Chroma | chroma |
| Classter | Multi-Purpose HTML Theme | classter |
| Coinpress | coinpress |
| ConFix – Expo & Events WordPress Theme | confix |
| Cookiteer | cookiteer |
| Craftis – Handcraft & Artisan Elementor Template Kit | craftis |
| DeepDigital – Web Design Agency WordPress Theme | deepdigital |
| Dental Clinic | dental |
| Dentalux | Dentist & Healthcare Site Template | dentalux |
| Don Peppe – Pizza and Fast Food WordPress Theme | donpeppe |
| DroneX | dronex |
| Edifice | edifice |
| EmojiNation | emojination |
| Equadio | equadio |
| Equestrian Centre – Horse-riding School Theme | equestrian-centre |
| Estate | estate |
| Etchy – Print Shop WordPress Theme | etchy |
| Felizia | Fertility Center & Medical WordPress Theme | felizia |
| FindAll – Business Directory WordPress Theme | findall |
| Foodie | foodie |
| Gaspard – Restaurant and Coffee Shop WordPress Theme | gaspard |
| Gioia – Modern Fashion Shop WordPress Theme | gioia |
| Global Logistics | globallogistics |
| Good Homes – Real Estate WordPress Theme | good-homes |
| Grand Wedding WordPress | grandwedding |
| Green Thumb | Gardening & Landscaping Services WP | greenthumb |
| Greenville | Private School & University Education WordPress Theme | greenville |
| Gridiron | American Football & NFL Team WordPress | gridiron |
| Grit – Life Coach & Business Coaching WordPress Theme | grit |
| Handyman – Home Services Booking App, Website & Admin Panel | handyman-services |
| Healer WordPress Themes, Plugins & Template Kits. | healer |
| Helion | Personal Portfolio & Agency WordPress Theme | helion |
| Hoverex | Cryptocurrency & ICO Elementor Template Kit | hoverex |
| Humanum | humanum |
| Hypnotherapy – Psychologist Theme | hypnotherapy |
| Invetex | invetex |
| Jardi | Winery, Vineyard & Wine Shop WordPress Theme | jardi |
| Justitia | Lawyer & Legal Adviser WordPress Theme | justitia |
| Kayon | kayon |
| Keenarch – Building & Construction WordPress Theme | keenarch |
| Kratz | kratz |
| Laurent – Elegant Restaurant WordPress Theme | laurent |
| Law Office | law-office |
| Lella – Hairdresser and Beauty Salon WordPress Theme | lella |
| Lendiz – Loan & Funding Agency WordPress Theme | lendiz |
| Lingvico | Language Center & Training Courses WordPress Theme | lingvico |
| Listify | listify |
| luxury-wine | luxury-wine |
| m2 | Construction and Tools Store WordPress Theme | m2-ce |
| Manoir | manoir |
| Maxify | maxify |
| Meals & Wheels | meals-wheels |
| MoneyFlow | moneyflow |
| Morning Records – Music Sound Studio WordPress Theme | morning-records |
| Motorix | motorix |
| Mounthood | Ski and Snowboarding HTML Template | mounthood |
| Mr. Cobbler | Custom Shoemaking & Footwear Repairs WordPress Theme | mr-cobbler |
| N7 | n7-golf-club |
| nelson | nelson |
| NeoBeat – Music WordPress Theme | neobeat |
| Nutrie – Health Coach and Nutrition WordPress Theme | nutrie |
| Nuts | nuts |
| OsTende | ostende |
| Pets Club – Pet Care WordPress Theme + Shop | petclub |
| Printy | printy |
| progress | progress |
| ProLingua | Translation Bureau & Interpreting Services WordPress Theme | prolingua |
| Prowess – Fitness and Gym WordPress Theme | prowess |
| Quanzo – Creative Portfolio Template Kit | quanzo |
| Remons – Car Rental Elementor Template Kit | remons |
| Restaurant WordPress Theme | Ratatouille | ratatouille |
| Roisin – Flower Shop and Florist WordPress Theme | roisin |
| Scientia | Public Library & Book Store Education WordPress Theme | scientia |
| ShiftCV – Blog Resume Portfolio WordPress Theme | shift-cv |
| Solaris | solaris |
| Stargaze | stargaze |
| Tediss | Play Area & Child Care Center WordPress Theme | tediss |
| The Qlean | the-qlean |
| Thebe – Portfolio WordPress Theme | thebe |
| TheBi – Photography WordPress Theme | thebi |
| Thecs – Portfolio WordPress Theme | thecs |
| Tour Booking WordPress Theme – Tripgo | tripgo |
| Translogic | Logistics & Shipment Transportation | translogic |
| Triompher | Golf Course & Sports Club WordPress Theme | triompher |
| Tuning | tuning |
| Unica – Event Planning & Wedding WordPress Theme | unica |
| VegaDays – Vegetarian Food Festival & Eco Event WordPress Theme | vegadays |
| Victo – Ultimate Responsive Magento 2 Theme | victo |
| Vixus – Business Startup Elementor Template Kit | vixus |
| Wanderland – Travel Blog | wanderland |
| Wizor's | Investments, Economics & Bankin WordPress Theme | wizors-investments |
| Yottis | yottis |
| Yungen | yungen |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (March 2, 2026 to March 8, 2026) appeared first on Wordfence.
Puedes consultar el artículo original aquí: https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/
2x all high threat vulnerability bounties (excluding 5,000,000+ installs)
+30% bonus for high threat vulnerabilities in software with 30,000+ active installs (excluding 5,000,000+ installs)
$300 extra for every 3 High Threat vulnerabilities submitted (minimum of 1,000 installs)