Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 43 de 70

Media

WordPress · Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)

CVE-2026-3722: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO). Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO): 0 hasta 4.9

Leer análisis
Alta

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-42683: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: n/a hasta 1.8.8

Leer análisis
Alta

WordPress · Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity

CVE-2026-42673: CWE-201: vulnerabilidad de seguridad en Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity

El registro oficial identifica la vulnerabilidad «CWE-201: vulnerabilidad de seguridad» en Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity. Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: n/a hasta 3.3.6

Leer análisis
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-9243: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.15

Leer análisis
Media

WordPress · Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

CVE-2026-8995: CWE-200: Exposición de información sensible a un actor no autorizado en Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls. Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls: 0 hasta 6.3.7

Leer análisis
Media

WordPress · Post Snippets – Custom WordPress Code Snippets Customizer

CVE-2026-7430: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Post Snippets – Custom WordPress Code Snippets Customizer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Post Snippets – Custom WordPress Code Snippets Customizer. Post Snippets – Custom WordPress Code Snippets Customizer: 0 hasta 4.0.19

Leer análisis
Media

WordPress · StatCounter – Free Real Time Visitor Stats

CVE-2026-6275: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en StatCounter – Free Real Time Visitor Stats

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en StatCounter – Free Real Time Visitor Stats. StatCounter – Free Real Time Visitor Stats: 0 hasta 2.1.1

Leer análisis
Media

WordPress · PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

CVE-2026-9618: CWE-352: vulnerabilidad de seguridad en PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI). PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI): 0 hasta 1.120.46

Leer análisis
Media

WordPress · FOX – Currency Switcher Professional for WooCommerce

CVE-2026-9241: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en FOX – Currency Switcher Professional for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en FOX – Currency Switcher Professional for WooCommerce. FOX – Currency Switcher Professional for WooCommerce: 0 hasta 1.4.6

Leer análisis
Media

WordPress · Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

CVE-2026-9015: CWE-862: Falta de autorización en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance. Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance: 0 hasta 1.42.0

Leer análisis
Alta

WordPress · Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-7797: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: 0 hasta 1.6.11.8

Leer análisis
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-7651: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.5

Leer análisis
Media

WordPress · Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

CVE-2026-7533: CWE-352: vulnerabilidad de seguridad en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Easy Digital Downloads – eCommerce Payments and Subscriptions made easy. Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 0 hasta 3.6.7

Leer análisis
Media

WordPress · PDF Embedder – PDF Viewer & Embed PDF Files for WordPress

CVE-2026-7526: CWE-200: Exposición de información sensible a un actor no autorizado en PDF Embedder – PDF Viewer & Embed PDF Files for WordPress

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en PDF Embedder – PDF Viewer & Embed PDF Files for WordPress. PDF Embedder – PDF Viewer & Embed PDF Files for WordPress: 0 hasta 4.9.3

Leer análisis
Alta

WordPress · HT Contact Form – Drag & Drop Form Builder for WordPress

CVE-2026-7052: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en HT Contact Form – Drag & Drop Form Builder for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en HT Contact Form – Drag & Drop Form Builder for WordPress. HT Contact Form – Drag & Drop Form Builder for WordPress: 0 hasta 2.8.2

Leer análisis
Media

WordPress · Photo Gallery by 10Web – Mobile-Friendly Image Gallery

CVE-2026-7048: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Photo Gallery by 10Web – Mobile-Friendly Image Gallery

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Photo Gallery by 10Web – Mobile-Friendly Image Gallery. Photo Gallery by 10Web – Mobile-Friendly Image Gallery: 0 hasta 1.8.40

Leer análisis
Media

WordPress · Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

CVE-2026-6937: CWE-862: Falta de autorización en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: 0 hasta 1.6.11.8

Leer análisis
Media

WordPress · Meta Field Block – Display custom fields in the Block Editor without coding

CVE-2026-3173: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Meta Field Block – Display custom fields in the Block Editor without coding

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Meta Field Block – Display custom fields in the Block Editor without coding. Meta Field Block – Display custom fields in the Block Editor without coding: 0 hasta 1.5.1

Leer análisis
Media

WordPress · CM Ad Changer – A simple tool to control and optimize your site's banners

CVE-2026-9236: CWE-352: vulnerabilidad de seguridad en CM Ad Changer – A simple tool to control and optimize your site's banners

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en CM Ad Changer – A simple tool to control and optimize your site's banners. CM Ad Changer – A simple tool to control and optimize your site's banners: 0 hasta 2.0.7

Leer análisis
Media

WordPress · BitForm – Data management solution for WordPress

CVE-2026-8891: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en BitForm – Data management solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BitForm – Data management solution for WordPress. BitForm – Data management solution for WordPress: 0 hasta 1.1.0

Leer análisis