Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

7.986 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 30 de 80

Crítica

WordPress · Spider Analyser – WordPress搜索引擎蜘蛛分析插件

CVE-2026-65553: CWE-94: Control incorrecto de la generación de código (Code Injection) en Spider Analyser – WordPress搜索引擎蜘蛛分析插件

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en Spider Analyser – WordPress搜索引擎蜘蛛分析插件. Spider Analyser – WordPress搜索引擎蜘蛛分析插件: n/a hasta 2.1.3

Leer análisis
Alta

WordPress · Formidable Forms Signature Online Contract Automation

CVE-2026-65523: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Formidable Forms Signature Online Contract Automation

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Formidable Forms Signature Online Contract Automation. Formidable Forms Signature Online Contract Automation: n/a hasta 2.0.1

Leer análisis
Media

WordPress · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress

CVE-2026-5391: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress. Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress: 0 hasta 5.3.2

Leer análisis
Media

WordPress · Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

CVE-2026-28146: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Unlimited Elements For Elementor (Free Widgets, Addons, Templates). Unlimited Elements For Elementor (Free Widgets, Addons, Templates): n/a hasta 2.0.14

Leer análisis
Alta

WordPress · TranslatePress – Translate Multilingual sites with AI Translation

CVE-2026-18510: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en TranslatePress – Translate Multilingual sites with AI Translation

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en TranslatePress – Translate Multilingual sites with AI Translation. TranslatePress – Translate Multilingual sites with AI Translation: 0 hasta 3.2.6

Leer análisis
Media

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-18501: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.69

Leer análisis
Media

WordPress · Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

CVE-2026-18400: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider. Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: 0 hasta 3.111.0

Leer análisis
Alta

WordPress · Forminator Forms – Contact Form, Payment Form & Custom Form Builder

CVE-2026-18325: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Forminator Forms – Contact Form, Payment Form & Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Forminator Forms – Contact Form, Payment Form & Custom Form Builder. Forminator Forms – Contact Form, Payment Form & Custom Form Builder: 0 hasta 1.56.1

Leer análisis
Alta

WordPress · FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP

CVE-2026-16636: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP. FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP: 0 hasta 2.2.95

Leer análisis
Alta

WordPress · Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps

CVE-2026-14829: CWE-284: vulnerabilidad de seguridad en Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps

El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps. Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps: 0 hasta 1.0.13

Leer análisis