Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 67 de 70

Media

WordPress · Orange Comfort+ accessibility toolbar for WordPress

CVE-2026-1808: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Orange Comfort+ accessibility toolbar for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Orange Comfort+ accessibility toolbar for WordPress. Orange Comfort+ accessibility toolbar for WordPress: 0 hasta 0.7

Leer análisis
Media

WordPress · Yoast SEO – Advanced SEO with real-time guidance and built-in AI

CVE-2026-1293: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Yoast SEO – Advanced SEO with real-time guidance and built-in AI

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Yoast SEO – Advanced SEO with real-time guidance and built-in AI. Yoast SEO – Advanced SEO with real-time guidance and built-in AI: 0 hasta 26.8

Leer análisis
Media

WordPress · Employee Directory – Staff Directory and Listing

CVE-2026-1279: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Employee Directory – Staff Directory and Listing

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Employee Directory – Staff Directory and Listing. Employee Directory – Staff Directory and Listing: 0 hasta 1.2.1

Leer análisis
Media

WordPress · Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)

CVE-2026-1228: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines). Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines): 0 hasta 1.3.3

Leer análisis
Media

WordPress · Robin Image Optimizer – Unlimited Image Optimization & WebP Converter

CVE-2026-1319: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Robin Image Optimizer – Unlimited Image Optimization & WebP Converter

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Robin Image Optimizer – Unlimited Image Optimization & WebP Converter. Robin Image Optimizer – Unlimited Image Optimization & WebP Converter: 0 hasta 2.0.2

Leer análisis
Alta

WordPress · All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink

CVE-2026-1294: CWE-918: vulnerabilidad de seguridad en All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink. All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink: 0 hasta 1.0.2

Leer análisis
Media

WordPress · ProfileGrid – User Profiles, Groups and Communities

CVE-2026-1271: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ProfileGrid – User Profiles, Groups and Communities

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ProfileGrid – User Profiles, Groups and Communities. ProfileGrid – User Profiles, Groups and Communities: 0 hasta 5.9.7.2

Leer análisis
Media

WordPress · ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

CVE-2026-1246: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF. ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF: 0 hasta 6.4.2

Leer análisis
Media

WordPress · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

CVE-2026-1447: CWE-352: vulnerabilidad de seguridad en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 1.19.2

Leer análisis
Alta

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-1058: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.35

Leer análisis
Media

WordPress · Spectra Gutenberg Blocks – Website Builder for the Block Editor

CVE-2026-0950: CWE-200: Exposición de información sensible a un actor no autorizado en Spectra Gutenberg Blocks – Website Builder for the Block Editor

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Spectra Gutenberg Blocks – Website Builder for the Block Editor. Spectra Gutenberg Blocks – Website Builder for the Block Editor: 0 hasta 2.19.17

Leer análisis
Media

WordPress · WP ULike – Like & Dislike Buttons for Engagement and Feedback

CVE-2026-0909: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en WP ULike – Like & Dislike Buttons for Engagement and Feedback

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WP ULike – Like & Dislike Buttons for Engagement and Feedback. WP ULike – Like & Dislike Buttons for Engagement and Feedback: 0 hasta 4.8.3.1

Leer análisis
Alta

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-0617: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.2.5

Leer análisis
Media

WordPress · SupportCandy – Helpdesk & Customer Support Ticket System

CVE-2026-1251: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en SupportCandy – Helpdesk & Customer Support Ticket System

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en SupportCandy – Helpdesk & Customer Support Ticket System. SupportCandy – Helpdesk & Customer Support Ticket System: 0 hasta 3.4.4

Leer análisis
Media

WordPress · SupportCandy – Helpdesk & Customer Support Ticket System

CVE-2026-0683: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en SupportCandy – Helpdesk & Customer Support Ticket System

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SupportCandy – Helpdesk & Customer Support Ticket System. SupportCandy – Helpdesk & Customer Support Ticket System: 0 hasta 3.4.4

Leer análisis