Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 60 de 70

Media

WordPress · RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

CVE-2026-2433: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging. RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging: 0 hasta 5.0.11

Leer análisis
Media

WordPress · CM Custom Reports – Flexible reporting to track what matters most

CVE-2026-2431: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CM Custom Reports – Flexible reporting to track what matters most

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CM Custom Reports – Flexible reporting to track what matters most. CM Custom Reports – Flexible reporting to track what matters most: 0 hasta 1.2.7

Leer análisis
Media

WordPress · WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

CVE-2026-2830: CWE-94: Control incorrecto de la generación de código (Code Injection) en WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets. WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets: 0 hasta 4.0.0

Leer análisis
Crítica

WordPress · WP Attractive Donations System - Easy Stripe & Paypal donations

CVE-2026-28115: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Attractive Donations System - Easy Stripe & Paypal donations

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Attractive Donations System - Easy Stripe & Paypal donations. WP Attractive Donations System - Easy Stripe & Paypal donations: 0 hasta 1.25

Leer análisis
Alta

WordPress · LambertGroup - AllInOne - Banner with Playlist

CVE-2026-28110: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LambertGroup - AllInOne - Banner with Playlist

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LambertGroup - AllInOne - Banner with Playlist. LambertGroup - AllInOne - Banner with Playlist: 0 hasta 3.8

Leer análisis
Alta

WordPress · LambertGroup - AllInOne - Banner with Thumbnails

CVE-2026-28108: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LambertGroup - AllInOne - Banner with Thumbnails

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LambertGroup - AllInOne - Banner with Thumbnails. LambertGroup - AllInOne - Banner with Thumbnails: 0 hasta 3.8

Leer análisis