Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

7.986 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 16 de 80

Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-77807: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 11.0.4

Leer análisis
Media

WordPress · Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

CVE-2026-85418: CWE-79: Cross-Site Scripting (XSS) en Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More. Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: 0 hasta 3.0.9

Leer análisis
Media

WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

CVE-2026-84908: CWE-862: Falta de autorización en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.13

Leer análisis
Alta

WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

CVE-2026-83593: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.7.3

Leer análisis
Alta

WordPress · WP Plugin Web / WP Plugin Crazy Domains / WP Module Data

CVE-2026-80099: CWE-287: Autenticación incorrecta en WP Plugin Web / WP Plugin Crazy Domains / WP Module Data

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en WP Plugin Web / WP Plugin Crazy Domains / WP Module Data. WP Plugin Web: 0 hasta 2.3.5; WP Plugin Crazy Domains: 0 hasta 2.5.2; WP Module Data: 0 hasta 2.9.7; WP Plugin Hostgator: 0 hasta 3.2.0; WP Plugin Bluehost: 0 hasta 4.19.0

Leer análisis
Media

WordPress · My Calendar – Accessible Event Manager

CVE-2026-77187: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en My Calendar – Accessible Event Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en My Calendar – Accessible Event Manager. My Calendar – Accessible Event Manager: 0 hasta 3.8.3

Leer análisis
Media

WordPress · My Calendar – Accessible Event Manager

CVE-2026-77186: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en My Calendar – Accessible Event Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en My Calendar – Accessible Event Manager. My Calendar – Accessible Event Manager: 0 hasta 3.8.3

Leer análisis
Alta

WordPress · FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment

CVE-2026-76801: CWE-269: Gestión incorrecta de privilegios en FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment. FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment: 0 hasta 3.1.10

Leer análisis
Alta

WordPress · User Role Editor – PublishPress Capabilities: Access Control and User Roles

CVE-2026-75927: CWE-269: Gestión incorrecta de privilegios en User Role Editor – PublishPress Capabilities: Access Control and User Roles

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en User Role Editor – PublishPress Capabilities: Access Control and User Roles. User Role Editor – PublishPress Capabilities: Access Control and User Roles: 0 hasta 2.50.0

Leer análisis
Media

WordPress · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-19800: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 1.31.0

Leer análisis
Media

WordPress · WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping

CVE-2026-19778: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping. WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping: 0 hasta 2.23.7

Leer análisis
Media

WordPress · Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

CVE-2026-17149: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred. Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred: 0 hasta 3.2.4

Leer análisis
Alta

WordPress · WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

CVE-2026-14989: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode. WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: 0 hasta 4.4.1

Leer análisis
Media

WordPress · Graphina – Charts and Graphs For Elementor

CVE-2026-13709: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Graphina – Charts and Graphs For Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Graphina – Charts and Graphs For Elementor. Graphina – Charts and Graphs For Elementor: 0 hasta 3.1.11

Leer análisis
Alta

WordPress · Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

CVE-2026-13359: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress. Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: 0 hasta 1.7.5

Leer análisis
Alta

WordPress · Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

CVE-2026-84820: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Unlimited Elements For Elementor (Free Widgets, Addons, Templates). Unlimited Elements For Elementor (Free Widgets, Addons, Templates): n/a hasta 2.0.17

Leer análisis