Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 16 de 47

Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-12165: CWE-269: Gestión incorrecta de privilegios en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 30.0.2

Leer análisis →
Media

WordPress · Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress

CVE-2026-12115: CWE-502: Deserialización de datos no confiables en Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress

El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress. Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress: 0 hasta 2.0.13

Leer análisis →
Alta

WordPress · Min Max Step Quantity Limits Manager for WooCommerce

CVE-2026-39437: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Min Max Step Quantity Limits Manager for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Min Max Step Quantity Limits Manager for WooCommerce. Min Max Step Quantity Limits Manager for WooCommerce: n/a hasta 5.2.2

Leer análisis →
Media

WordPress · Secure Client Portal and Private File Sharing Plugin – User Private Files

CVE-2026-10093: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Secure Client Portal and Private File Sharing Plugin – User Private Files

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Secure Client Portal and Private File Sharing Plugin – User Private Files. Secure Client Portal and Private File Sharing Plugin – User Private Files: 0 hasta 2.1.6

Leer análisis →
Crítica

WordPress · Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms

CVE-2026-9691: CWE-502: Deserialización de datos no confiables en Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms

El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms. Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: n/a hasta 1.1.1

Leer análisis →