Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 63 de 70

Alta

WordPress · WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

CVE-2026-1720: CWE-862: Falta de autorización en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation. WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation: 0 hasta 1.4.24

Leer análisis
Media

WordPress · My Calendar – Accessible Event Manager

CVE-2026-2355: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en My Calendar – Accessible Event Manager

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en My Calendar – Accessible Event Manager. My Calendar – Accessible Event Manager: 0 hasta 3.7.3

Leer análisis
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-2289: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.3

Leer análisis
Media

WordPress · Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder

CVE-2026-1674: CWE-862: Falta de autorización en Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder. Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder: 0 hasta 1.6.0

Leer análisis
Media

WordPress · Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

CVE-2026-1651: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress. Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: 0 hasta 5.9.16

Leer análisis
Media

WordPress · Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

CVE-2026-1236: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More. Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More: 0 hasta 1.12.3

Leer análisis
Alta

WordPress · WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

CVE-2026-2568: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: 0 hasta 1.1.5

Leer análisis
Alta

WordPress · Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

CVE-2026-2269: CWE-434: vulnerabilidad de seguridad en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin: 0 hasta 7.0.0.3

Leer análisis
Crítica

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1492: CWE-269: Gestión incorrecta de privilegios en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis
Media

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-1487: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.2.7

Leer análisis
Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-3180: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 28.1.4

Leer análisis
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-2356: CWE-284: vulnerabilidad de seguridad en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis
Alta

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1779: CWE-288: vulnerabilidad de seguridad en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-288: vulnerabilidad de seguridad» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis
Alta

WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

CVE-2026-1565: CWE-434: vulnerabilidad de seguridad en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration: 0 hasta 4.2.8

Leer análisis
Media

WordPress · Secure Copy Content Protection and Content Locking

CVE-2026-2367: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Secure Copy Content Protection and Content Locking

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Secure Copy Content Protection and Content Locking. Secure Copy Content Protection and Content Locking: 0 hasta 5.0.1

Leer análisis
Alta

WordPress · Advanced Woo Labels – Product Labels & Badges for WooCommerce

CVE-2026-1929: CWE-94: Control incorrecto de la generación de código (Code Injection) en Advanced Woo Labels – Product Labels & Badges for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en Advanced Woo Labels – Product Labels & Badges for WooCommerce. Advanced Woo Labels – Product Labels & Badges for WooCommerce: 0 hasta 2.36

Leer análisis
Media

WordPress · Rise Blocks – A Complete Gutenberg Page Builder

CVE-2026-1614: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Rise Blocks – A Complete Gutenberg Page Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Rise Blocks – A Complete Gutenberg Page Builder. Rise Blocks – A Complete Gutenberg Page Builder: 0 hasta 3.7

Leer análisis
Crítica

WordPress · ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor

CVE-2026-23693: CWE-306: vulnerabilidad de seguridad en ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor

El registro oficial identifica la vulnerabilidad «CWE-306: vulnerabilidad de seguridad» en ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor. ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor: 0 hasta 3.7.9

Leer análisis
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-2385: CWE-345: vulnerabilidad de seguridad en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.7

Leer análisis
Alta

WordPress · PixelYourSite – Your smart PIXEL (TAG) Manager

CVE-2026-27072: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en PixelYourSite – Your smart PIXEL (TAG) Manager

El registro oficial identifica la vulnerabilidad «Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en PixelYourSite – Your smart PIXEL (TAG) Manager. PixelYourSite – Your smart PIXEL (TAG) Manager: 0 hasta 11.2.0.1

Leer análisis
Media

WordPress · Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

CVE-2026-2486: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits. Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits: 0 hasta 2.1.1

Leer análisis