Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

7.986 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 2 de 80

Alta

WordPress · Kirki – Freeform Page Builder, Website Builder & Customizer

CVE-2026-102173: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Kirki – Freeform Page Builder, Website Builder & Customizer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Kirki – Freeform Page Builder, Website Builder & Customizer. Kirki – Freeform Page Builder, Website Builder & Customizer: 0 hasta 6.3.1

Leer análisis
Alta

WordPress · Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

CVE-2026-75962: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App. Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App: 0 hasta 4.0.1

Leer análisis
Alta

WordPress · WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

CVE-2026-42636: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Cookie Notice for GDPR, CCPA & ePrivacy Consent. WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: n/a hasta 4.4.6

Leer análisis
Alta

WordPress · Video Background Block – Use video as background in the section.

CVE-2026-42634: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Video Background Block – Use video as background in the section.

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Video Background Block – Use video as background in the section.. Video Background Block – Use video as background in the section.: n/a hasta 2.0.3

Leer análisis
Crítica

WordPress · Newsletter Subscription Form – User Subscriptions Form, Capture Email

CVE-2026-41555: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Newsletter Subscription Form – User Subscriptions Form, Capture Email

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Newsletter Subscription Form – User Subscriptions Form, Capture Email. Newsletter Subscription Form – User Subscriptions Form, Capture Email: n/a hasta 1.5.9

Leer análisis
Alta

WordPress · CF7 Views – Complete Entry Management for Contact Form 7

CVE-2026-40807: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CF7 Views – Complete Entry Management for Contact Form 7

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CF7 Views – Complete Entry Management for Contact Form 7. CF7 Views – Complete Entry Management for Contact Form 7: n/a hasta 3.2.6

Leer análisis
Alta

WordPress · Blog, Posts and Category Filter for Elementor

CVE-2026-40806: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Blog, Posts and Category Filter for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Blog, Posts and Category Filter for Elementor. Blog, Posts and Category Filter for Elementor: n/a hasta 2.1.0

Leer análisis
Alta

WordPress · Ansar Import – One Click Starter Sites – for Elementor & Themes

CVE-2026-39778: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Ansar Import – One Click Starter Sites – for Elementor & Themes

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ansar Import – One Click Starter Sites – for Elementor & Themes. Ansar Import – One Click Starter Sites – for Elementor & Themes: n/a hasta 2.1.2

Leer análisis
Crítica

WordPress · Radius Booking — Booking Calendar for Appointments & Services

CVE-2026-39764: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Radius Booking — Booking Calendar for Appointments & Services

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Radius Booking — Booking Calendar for Appointments & Services. Radius Booking — Booking Calendar for Appointments & Services: n/a hasta 1.0.19

Leer análisis
Alta

WordPress · StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart

CVE-2026-39750: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart. StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart: n/a hasta 2.0.6

Leer análisis