WordPress · WOLF
CVE-2026-14234: CWE-79: Cross-Site Scripting (XSS) en WOLF
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en WOLF. WOLF: 0 hasta 1.1.0
DIRECTORIO CVE · 2026
6.969 registros, ordenados por fecha oficial de publicación descendente.
Mostrando 100 registros · Página 24 de 70
WordPress · WOLF
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en WOLF. WOLF: 0 hasta 1.1.0
WordPress · Easy Appointments
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Easy Appointments. Easy Appointments: 0 hasta 3.12.28
WordPress · PayU CommercePro Plugin
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en PayU CommercePro Plugin. PayU CommercePro Plugin: 0 hasta 3.9.0
WordPress · UsersWP
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en UsersWP. UsersWP: 0 hasta 1.2.67
WordPress · PhotoSwipe
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en PhotoSwipe. PhotoSwipe: 0 hasta 4.1.1.1
WordPress · Database for CF7
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Database for CF7. Database for CF7: 0 hasta 1.2.6
WordPress · Streamit
El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en Streamit. Streamit: 0 hasta 4.5.0
WordPress · Newsletters
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Newsletters. Newsletters: 0 hasta 4.15
WordPress · Newsletters
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Newsletters. Newsletters: 0 hasta 4.15
WordPress · Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy. Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 0 hasta 3.6.9
WordPress · Wholesale for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Wholesale for WooCommerce. Wholesale for WooCommerce: 0 hasta 2.0.5
WordPress · wp-media-folder-addon
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en wp-media-folder-addon. wp-media-folder-addon: 0 hasta 4.1.7
WordPress · WP-Lister Lite for eBay
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP-Lister Lite for eBay. WP-Lister Lite for eBay: 0 hasta 3.8.8
WordPress · ShinyStat Analytics
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en ShinyStat Analytics. ShinyStat Analytics: 1.0.12 hasta 1.0.17
WordPress · Chaty Pro
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Chaty Pro. Chaty Pro: 0 hasta 3.5.5
WordPress · SpeedyCache – Cache, Optimization, Performance
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en SpeedyCache – Cache, Optimization, Performance. SpeedyCache – Cache, Optimization, Performance: 0 hasta 1.3.8
WordPress · Media Cleaner: Clean your WordPress!
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Media Cleaner: Clean your WordPress!. Media Cleaner: Clean your WordPress!: 0 hasta 7.0.3
WordPress · WordPress-Coding-Standards
El registro oficial identifica la vulnerabilidad «CWE-95: vulnerabilidad de seguridad» en WordPress-Coding-Standards. WordPress-Coding-Standards: >= 0.14.1, < 3.4.1
WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5
WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.4.5
WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.5.9
WordPress · WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: 0 hasta 8.5.9
WordPress · Advanced Form Integration — Connect Forms to 200+ Apps
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Advanced Form Integration — Connect Forms to 200+ Apps. Advanced Form Integration — Connect Forms to 200+ Apps: 0 hasta 2.6.0
WordPress · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots. Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots: 0 hasta 2.15.19
WordPress · WP Password Policy
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en WP Password Policy. WP Password Policy: 0 hasta 3.7.1
WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.9.1
WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7
WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7
WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7
WordPress · Tutor LMS – eLearning and online course solution
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 4.0.1
WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0
WordPress · Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates. Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates: 0 hasta 2.2.11
WordPress · Plugin Organizer
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Plugin Organizer. Plugin Organizer: 0 hasta 10.2.4
WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.9
WordPress · WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode. WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: 0 hasta 4.3.7
WordPress · Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: 0 hasta 7.3.2
WordPress · Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions. Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: 0 hasta 3.8.1
WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
El registro oficial identifica la vulnerabilidad «CWE-288: vulnerabilidad de seguridad» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.7
WordPress · Demi – One Click Demo Import, Backup & Site Migration
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Demi – One Click Demo Import, Backup & Site Migration. Demi – One Click Demo Import, Backup & Site Migration: 0 hasta 0.0.8
WordPress · FluentCart A New Era of eCommerce
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en FluentCart A New Era of eCommerce. FluentCart A New Era of eCommerce: 0 hasta 1.4.0
WordPress · Tablesome Table
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Tablesome Table. Tablesome Table: 0 hasta 1.1.31
WordPress · Database for Contact Form 7, WPforms, Elementor forms
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Database for Contact Form 7, WPforms, Elementor forms. Database for Contact Form 7, WPforms, Elementor forms: 0 hasta 1.5.3
WordPress · Quiz and Survey Master (QSM)
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Quiz and Survey Master (QSM). Quiz and Survey Master (QSM): 0 hasta 11.1.5
WordPress · Event Tickets and Registration
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Event Tickets and Registration. Event Tickets and Registration: 0 hasta 5.28.4
WordPress · Web Directory Free
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Web Directory Free. Web Directory Free: 0 hasta 1.7.13
WordPress · TrueBooker
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en TrueBooker. TrueBooker: 0 hasta 1.2.4
WordPress · Online Scheduling and Appointment Booking System – Bookly
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Online Scheduling and Appointment Booking System – Bookly. Online Scheduling and Appointment Booking System – Bookly: 0 hasta 27.5
WordPress · Demi – One Click Demo Import, Backup & Site Migration
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Demi – One Click Demo Import, Backup & Site Migration. Demi – One Click Demo Import, Backup & Site Migration: 0 hasta 0.0.7
WordPress · Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress. Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress: 0 hasta 4.4.1
WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0
WordPress · TrueBooker – Appointment Booking and Scheduler System
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en TrueBooker – Appointment Booking and Scheduler System. TrueBooker – Appointment Booking and Scheduler System: 0 hasta 1.2.2
WordPress · StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce: 0 hasta 2.1.0
WordPress · Premium Packages – Sell Digital Products Securely
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Premium Packages – Sell Digital Products Securely. Premium Packages – Sell Digital Products Securely: 0 hasta 6.2.0
WordPress · WP Fast Total Search – The Power of Indexed Search
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Fast Total Search – The Power of Indexed Search. WP Fast Total Search – The Power of Indexed Search: 0 hasta 1.80.280
WordPress · PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer. PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer: 0 hasta 1.1.0
WordPress · Shortcodify
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Shortcodify. Shortcodify: 0 hasta 1.4.3
WordPress · PickPlugins Question Answer
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en PickPlugins Question Answer. PickPlugins Question Answer: 0 hasta 1.2.73
WordPress · bookingpress-appointment-booking-pro
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en bookingpress-appointment-booking-pro. bookingpress-appointment-booking-pro: 0 hasta 5.7.3
WordPress · Gillion
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Gillion. Gillion: n/a hasta 4.13
WordPress · Easy Digital Downloads
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Easy Digital Downloads. Easy Digital Downloads: n/a hasta 3.6.9
WordPress · Checkout Field Editor for WooCommerce – Checkout Manager
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Checkout Field Editor for WooCommerce – Checkout Manager. Checkout Field Editor for WooCommerce – Checkout Manager: n/a hasta 3.0.5
WordPress · Insert Headers and Footers Code – HT Script
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Insert Headers and Footers Code – HT Script. Insert Headers and Footers Code – HT Script: n/a hasta 1.1.8
WordPress · Xendit Payment
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Xendit Payment. Xendit Payment: n/a hasta 7.1.0
WordPress · Gallery PhotoBlocks
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Gallery PhotoBlocks. Gallery PhotoBlocks: n/a hasta 1.3.3
WordPress · Open User Map
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Open User Map. Open User Map: n/a hasta 1.4.46
WordPress · YayPricing
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en YayPricing. YayPricing: n/a hasta 3.5.6
WordPress · Exclusive Addons Elementor
El registro oficial identifica la vulnerabilidad «CWE-497: vulnerabilidad de seguridad» en Exclusive Addons Elementor. Exclusive Addons Elementor: n/a hasta 2.8.0
WordPress · Feedzy
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Feedzy. Feedzy: n/a hasta 5.2.4
WordPress · Photonic Gallery & Lightbox for Flickr, SmugMug & Others
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Photonic Gallery & Lightbox for Flickr, SmugMug & Others. Photonic Gallery & Lightbox for Flickr, SmugMug & Others: n/a hasta 3.33
WordPress · Location Weather
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Location Weather. Location Weather: n/a hasta 3.0.6
WordPress · WP Google Review Slider
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WP Google Review Slider. WP Google Review Slider: n/a hasta 18.4
WordPress · WP Google Review Slider
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Google Review Slider. WP Google Review Slider: n/a hasta 18.4
WordPress · Visual Composer Website Builder
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Visual Composer Website Builder. Visual Composer Website Builder: n/a hasta 45.15.0
WordPress · Event Tickets
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Event Tickets. Event Tickets: n/a hasta 5.29.0.1
WordPress · MapPress Maps for WordPress
El registro oficial identifica la vulnerabilidad «CWE-497: vulnerabilidad de seguridad» en MapPress Maps for WordPress. MapPress Maps for WordPress: n/a hasta 2.97.6
WordPress · Orbit Fox by ThemeIsle
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Orbit Fox by ThemeIsle. Orbit Fox by ThemeIsle: n/a hasta 3.0.7
WordPress · BetterDocs
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BetterDocs. BetterDocs: n/a hasta 4.6.2
WordPress · WordPress Social Login and Register
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WordPress Social Login and Register. WordPress Social Login and Register: n/a hasta 7.8.0
WordPress · AffiliateX
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en AffiliateX. AffiliateX: n/a hasta 2.3.5
WordPress · Abandoned Cart Lite for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Abandoned Cart Lite for WooCommerce. Abandoned Cart Lite for WooCommerce: n/a hasta 6.8.0
WordPress · Anti Spam and list cleaner – AcyChecker
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Anti Spam and list cleaner – AcyChecker. Anti Spam and list cleaner – AcyChecker: n/a hasta 1.8.1
WordPress · Contest Gallery
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Contest Gallery. Contest Gallery: n/a hasta 30.0.6
WordPress · Kali Forms
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Kali Forms. Kali Forms: n/a hasta 2.4.18
WordPress · Ad Invalid Click Protector (AICP)
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Ad Invalid Click Protector (AICP). Ad Invalid Click Protector (AICP): n/a hasta 1.3.0
WordPress · BackWPup
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BackWPup. BackWPup: n/a hasta 5.7.4
WordPress · FormCraft
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en FormCraft. FormCraft: n/a hasta 3.9.15
WordPress · GiveWP
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GiveWP. GiveWP: n/a hasta 4.16.3
WordPress · GetGenie
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GetGenie. GetGenie: n/a hasta 4.4.3
WordPress · Ultimate Addons for Contact Form 7
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ultimate Addons for Contact Form 7. Ultimate Addons for Contact Form 7: n/a hasta 3.5.45
WordPress · Message Filter for Contact Form 7
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Message Filter for Contact Form 7. Message Filter for Contact Form 7: n/a hasta 1.6.3.9
WordPress · Spam protection, AntiSpam, FireWall by CleanTalk
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Spam protection, AntiSpam, FireWall by CleanTalk. Spam protection, AntiSpam, FireWall by CleanTalk: n/a hasta 6.82
WordPress · Kirki
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Kirki. Kirki: n/a hasta 6.0.13
WordPress · Thrive Leads Version
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Thrive Leads Version. Thrive Leads Version: n/a hasta 10.9.2
WordPress · ЮKassa для WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-201: vulnerabilidad de seguridad» en ЮKassa для WooCommerce. ЮKassa для WooCommerce: n/a hasta 2.16.1
WordPress · RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg. RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg: n/a hasta 1.5.1
WordPress · miniorange otp verification
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en miniorange otp verification. miniorange otp verification: n/a hasta 5.5.1
WordPress · Simple Link Directory Pro
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Simple Link Directory Pro. Simple Link Directory Pro: n/a hasta 15.0.6
WordPress · FundEngine
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en FundEngine. FundEngine: n/a hasta 1.7.8
WordPress · RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg. RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg: n/a hasta 1.5.1
WordPress · Booking Calendar
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Booking Calendar. Booking Calendar: n/a hasta 11.4.2