Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 19 de 47

Media

WordPress · FastPicker, an order picker and order management system (oms) for WooCommerce on steroids

CVE-2026-8904: CWE-352: vulnerabilidad de seguridad en FastPicker, an order picker and order management system (oms) for WooCommerce on steroids

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en FastPicker, an order picker and order management system (oms) for WooCommerce on steroids. FastPicker, an order picker and order management system (oms) for WooCommerce on steroids: 0 hasta 1.0.2

Leer análisis →
Media

WordPress · Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

CVE-2026-8677: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages. Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: 0 hasta 1.3.3

Leer análisis →
Media

WordPress · MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-8599: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 2.0.4

Leer análisis →
Media

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

CVE-2026-4058: CWE-862: Falta de autorización en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration: 0 hasta 4.3.2

Leer análisis →
Media

WordPress · Photo Gallery by 10Web – Mobile-Friendly Image Gallery

CVE-2026-9829: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Photo Gallery by 10Web – Mobile-Friendly Image Gallery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Photo Gallery by 10Web – Mobile-Friendly Image Gallery. Photo Gallery by 10Web – Mobile-Friendly Image Gallery: 0 hasta 1.8.41

Leer análisis →
Media

WordPress · WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters

CVE-2026-9594: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters. WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters: 0 hasta 4.9.4

Leer análisis →
Media

WordPress · Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

CVE-2026-9281: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits. Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits: 0 hasta 3.1.0

Leer análisis →
Media

WordPress · Ad Inserter – Ad Manager & AdSense Ads

CVE-2026-9280: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Ad Inserter – Ad Manager & AdSense Ads

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ad Inserter – Ad Manager & AdSense Ads. Ad Inserter – Ad Manager & AdSense Ads: 0 hasta 2.8.15

Leer análisis →
Media

WordPress · Drag and Drop Multiple File Upload for Contact Form 7

CVE-2026-8991: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Drag and Drop Multiple File Upload for Contact Form 7

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Drag and Drop Multiple File Upload for Contact Form 7. Drag and Drop Multiple File Upload for Contact Form 7: 0 hasta 1.3.9.7

Leer análisis →
Media

WordPress · OptinCraft – Drag & Drop Optins & Popup Builder for WordPress

CVE-2026-8978: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en OptinCraft – Drag & Drop Optins & Popup Builder for WordPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en OptinCraft – Drag & Drop Optins & Popup Builder for WordPress. OptinCraft – Drag & Drop Optins & Popup Builder for WordPress: 0 hasta 1.2.0

Leer análisis →
Alta

WordPress · Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More

CVE-2026-8901: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More. Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More: 0 hasta 1.0.15

Leer análisis →
Alta

WordPress · All-In-One Security (AIOS) – Security and Firewall

CVE-2026-8438: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en All-In-One Security (AIOS) – Security and Firewall

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en All-In-One Security (AIOS) – Security and Firewall. All-In-One Security (AIOS) – Security and Firewall: 0 hasta 5.4.7

Leer análisis →
Media

WordPress · EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more

CVE-2026-7796: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more. EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more: 0 hasta 4.5.3

Leer análisis →
Media

WordPress · WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

CVE-2026-7792: CWE-345: vulnerabilidad de seguridad en WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More. WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More: 0 hasta 1.10.0.4

Leer análisis →
Media

WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-7665: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Essential Addons for Elementor – Popular Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.6.4

Leer análisis →
Alta

WordPress · WP User Manager – User Profile Builder & Membership

CVE-2026-9290: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en WP User Manager – User Profile Builder & Membership

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en WP User Manager – User Profile Builder & Membership. WP User Manager – User Profile Builder & Membership: 0 hasta 2.9.17

Leer análisis →
Media

WordPress · RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

CVE-2026-8976: CWE-862: Falta de autorización en RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator. RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: 0 hasta 5.1.7

Leer análisis →
Media

WordPress · Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

CVE-2026-6448: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker. Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: 0 hasta 11.1.2

Leer análisis →
Media

WordPress · Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More

CVE-2026-10038: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More. Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More: 0 hasta 1.8.11.1

Leer análisis →
Alta

WordPress · Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

CVE-2026-10586: CWE-918: vulnerabilidad de seguridad en Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns. Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns: 0 hasta 6.1.3

Leer análisis →