Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

4.697 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 40 de 47

Alta

WordPress · WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

CVE-2026-1720: CWE-862: Falta de autorización en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation. WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation: 0 hasta 1.4.24

Leer análisis →
Media

WordPress · My Calendar – Accessible Event Manager

CVE-2026-2355: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en My Calendar – Accessible Event Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en My Calendar – Accessible Event Manager. My Calendar – Accessible Event Manager: 0 hasta 3.7.3

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-2289: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.3

Leer análisis →
Media

WordPress · Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder

CVE-2026-1674: CWE-862: Falta de autorización en Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder. Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder: 0 hasta 1.6.0

Leer análisis →
Media

WordPress · Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

CVE-2026-1651: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress. Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: 0 hasta 5.9.16

Leer análisis →
Media

WordPress · Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

CVE-2026-1236: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More. Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More: 0 hasta 1.12.3

Leer análisis →
Alta

WordPress · WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

CVE-2026-2568: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: 0 hasta 1.1.5

Leer análisis →
Alta

WordPress · Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

CVE-2026-2269: CWE-434: vulnerabilidad de seguridad en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: 0 hasta 7.0.0.3

Leer análisis →
Crítica

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1492: CWE-269: Gestión incorrecta de privilegios en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis →
Media

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-1487: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.2.7

Leer análisis →
Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-3180: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 28.1.4

Leer análisis →
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-2356: CWE-284: vulnerabilidad de seguridad en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis →
Alta

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1779: CWE-288: vulnerabilidad de seguridad en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-288: vulnerabilidad de seguridad» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis →
Alta

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

CVE-2026-1565: CWE-434: vulnerabilidad de seguridad en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration: 0 hasta 4.2.8

Leer análisis →
Media

WordPress · Secure Copy Content Protection and Content Locking

CVE-2026-2367: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Secure Copy Content Protection and Content Locking

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Secure Copy Content Protection and Content Locking. Secure Copy Content Protection and Content Locking: 0 hasta 5.0.1

Leer análisis →
Alta

WordPress · Advanced Woo Labels – Product Labels & Badges for WooCommerce

CVE-2026-1929: CWE-94: Control incorrecto de la generación de código (Code Injection) en Advanced Woo Labels – Product Labels & Badges for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en Advanced Woo Labels – Product Labels & Badges for WooCommerce. Advanced Woo Labels – Product Labels & Badges for WooCommerce: 0 hasta 2.36

Leer análisis →
Media

WordPress · Rise Blocks – A Complete Gutenberg Page Builder

CVE-2026-1614: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Rise Blocks – A Complete Gutenberg Page Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Rise Blocks – A Complete Gutenberg Page Builder. Rise Blocks – A Complete Gutenberg Page Builder: 0 hasta 3.7

Leer análisis →