WordPress · MultiVendorX
CVE-2026-74926: CWE-862: Falta de autorización en MultiVendorX
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en MultiVendorX. MultiVendorX: 5.0.0 hasta 5.0.16
DIRECTORIO CVE · 2026
6.969 registros, ordenados por fecha oficial de publicación descendente.
Mostrando 100 registros · Página 4 de 70
WordPress · MultiVendorX
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en MultiVendorX. MultiVendorX: 5.0.0 hasta 5.0.16
WordPress · Bold Page Builder
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Bold Page Builder. Bold Page Builder: 0 hasta 5.9.6
WordPress · Formidable Forms
El registro oficial identifica la vulnerabilidad «CWE-74: vulnerabilidad de seguridad» en Formidable Forms. Formidable Forms: 6.34 hasta 6.35
WordPress · WP-Lister Lite for eBay
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP-Lister Lite for eBay. WP-Lister Lite for eBay: 0 hasta 3.8.9
WordPress · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots. Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots: 0 hasta 2.15.22
WordPress · WP Directory Kit
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Directory Kit. WP Directory Kit: 0 hasta 1.5.4
WordPress · TrueBooker – Appointment Booking and Scheduler System
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en TrueBooker – Appointment Booking and Scheduler System. TrueBooker – Appointment Booking and Scheduler System: 0 hasta 1.2.3
WordPress · Royal Addons for Elementor
El registro oficial identifica la vulnerabilidad «CWE-116: vulnerabilidad de seguridad» en Royal Addons for Elementor. Royal Addons for Elementor: 0 hasta 1.7.1067
WordPress · JetFormBuilder — Dynamic Blocks Form Builder
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en JetFormBuilder — Dynamic Blocks Form Builder. JetFormBuilder — Dynamic Blocks Form Builder: 0 hasta 3.6.2
WordPress · Advanced Popups
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Advanced Popups. Advanced Popups: 0 hasta 1.2.3
WordPress · Ad Inserter – Ad Manager & AdSense Ads
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Ad Inserter – Ad Manager & AdSense Ads. Ad Inserter – Ad Manager & AdSense Ads: 0 hasta 2.8.16
WordPress · MotoPress Hotel Booking
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en MotoPress Hotel Booking. MotoPress Hotel Booking: 0 hasta 6.2.4
WordPress · design-scuole-wordpress-theme
El registro oficial identifica la vulnerabilidad «CWE-601: vulnerabilidad de seguridad» en design-scuole-wordpress-theme. design-scuole-wordpress-theme: 1.0 hasta 2.17.3
WordPress · AI Engine – The Chatbot, AI Framework & MCP for WordPress
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en AI Engine – The Chatbot, AI Framework & MCP for WordPress. AI Engine – The Chatbot, AI Framework & MCP for WordPress: 0 hasta 3.7.7
WordPress · JWT Authentication for WP REST APIs
El registro oficial identifica la vulnerabilidad «Vulnerabilidad de seguridad» en JWT Authentication for WP REST APIs. JWT Authentication for WP REST APIs: 0 hasta 4.8.0
WordPress · design-scuole-wordpress-theme
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en design-scuole-wordpress-theme. design-scuole-wordpress-theme: 1.0 hasta 2.18.2
WordPress · design-scuole-wordpress-theme
El registro oficial identifica la vulnerabilidad «CWE-862» en design-scuole-wordpress-theme. design-scuole-wordpress-theme: 1.0 hasta 2.17.3
WordPress · design-scuole-wordpress-theme
El registro oficial identifica la vulnerabilidad «CWE-22» en design-scuole-wordpress-theme. design-scuole-wordpress-theme: 2.6.0 hasta 2.18.1
WordPress · Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors. Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors: 0 hasta 4.15.0
WordPress · ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets. ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets: 0 hasta 4.9.5
WordPress · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce. Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce: 0 hasta 4.1.23
WordPress · WP Directory Kit
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en WP Directory Kit. WP Directory Kit: 0 hasta 1.5.7
WordPress · Job Postings
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Job Postings. Job Postings: 0 hasta 2.8.1
WordPress · WP Directory Kit
El registro oficial identifica la vulnerabilidad «CWE-89: SQL Injection» en WP Directory Kit. WP Directory Kit: 0 hasta 1.5.7
WordPress · WP Directory Kit
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en WP Directory Kit. WP Directory Kit: 0 hasta 1.5.7
WordPress · 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery. 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery: 0 hasta 1.16.20
WordPress · Bridge - Creative Multipurpose WordPress Theme
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Bridge - Creative Multipurpose WordPress Theme. Bridge - Creative Multipurpose WordPress Theme: 0 hasta 30.8.9.1
WordPress · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce. Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce: 0 hasta 4.1.23
WordPress · Consulting - Business, Finance WordPress Theme
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Consulting - Business, Finance WordPress Theme. Consulting - Business, Finance WordPress Theme: 0 hasta 6.7.16
WordPress · Domain For Sale
El registro oficial identifica la vulnerabilidad «Falta de autorización» en Domain For Sale. Domain For Sale: 0 hasta 3.5.2
WordPress · Really Simple Security
El registro oficial identifica la vulnerabilidad «Falta de autorización» en Really Simple Security. Really Simple Security: 0 hasta 9.8.2
WordPress · Really Simple Security
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Really Simple Security. Really Simple Security: 9.5.10.1 hasta 9.8.1
WordPress · Quads Ads Manager for Google AdSense
El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en Quads Ads Manager for Google AdSense. Quads Ads Manager for Google AdSense: 3.0.4 hasta 3.0.5
WordPress · Bookit — Booking & Appointment Calendar
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en Bookit — Booking & Appointment Calendar. Bookit — Booking & Appointment Calendar: 0 hasta 2.6.0.1
WordPress · rtMedia for WordPress, BuddyPress and bbPress
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en rtMedia for WordPress, BuddyPress and bbPress. rtMedia for WordPress, BuddyPress and bbPress: 0 hasta 4.7.12
WordPress · MDJM Event Management / Mobile Events Manager
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en MDJM Event Management / Mobile Events Manager. MDJM Event Management: 0 hasta 1.7.8.5; Mobile Events Manager: 0 hasta 1.4.8.3
WordPress · YouTube Embed
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en YouTube Embed. YouTube Embed: 10.0 hasta 10.3
WordPress · Simple Membership
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Simple Membership. Simple Membership: 0 hasta 4.7.8
WordPress · User Registration & Membership
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en User Registration & Membership. User Registration & Membership: 5.0 hasta 5.2.8
WordPress · User Registration & Membership
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en User Registration & Membership. User Registration & Membership: 4.4.6 hasta 5.2.8
WordPress · Hoo Companion
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Hoo Companion. Hoo Companion: 1.0.2 hasta 1.0.2
WordPress · CryptoPayment Gateway
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en CryptoPayment Gateway. CryptoPayment Gateway: 1.2.1 hasta 1.2.2
WordPress · User Registration & Membership
El registro oficial identifica la vulnerabilidad «CWE-601: vulnerabilidad de seguridad» en User Registration & Membership. User Registration & Membership: 0 hasta 5.2.8
WordPress · User Registration & Membership
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en User Registration & Membership. User Registration & Membership: 0 hasta 5.2.8
WordPress · Contact Form to Chat Apps | Click to Chat to Order
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en Contact Form to Chat Apps | Click to Chat to Order. Contact Form to Chat Apps | Click to Chat to Order: 0 hasta 2.15.8
WordPress · GenieWords
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en GenieWords. GenieWords: 1.5.27 hasta 1.5.34
WordPress · Product XML Feed Manager for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Product XML Feed Manager for WooCommerce. Product XML Feed Manager for WooCommerce: 0 hasta 3.1.1
WordPress · WPBot
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en WPBot. WPBot: 0 hasta 8.5.7
WordPress · WPBot
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en WPBot. WPBot: 8.4.9 hasta 8.6.0
WordPress · Rox Appointment Booking
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Rox Appointment Booking. Rox Appointment Booking: 1.0.9 hasta 1.2.3
WordPress · Rox Appointment Booking
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Rox Appointment Booking. Rox Appointment Booking: 0 hasta 1.2.0
WordPress · Rox Appointment Booking
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Rox Appointment Booking. Rox Appointment Booking: 0 hasta 1.2.0
WordPress · YayPricing
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en YayPricing. YayPricing: 0 hasta 3.5.7
WordPress · Zonify
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en Zonify. Zonify: 0 hasta 1.0.5
WordPress · Sprout Invoices
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Sprout Invoices. Sprout Invoices: 0 hasta 20.8.16
WordPress · Add User Autocomplete
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Add User Autocomplete. Add User Autocomplete: 0 hasta 1.2
WordPress · WP Highlight Box
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en WP Highlight Box. WP Highlight Box: 0 hasta 1.0
WordPress · WP Component
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en WP Component. WP Component: 0 hasta 2.2.4
WordPress · GEO my WP
El registro oficial identifica la vulnerabilidad «CWE-98: vulnerabilidad de seguridad» en GEO my WP. GEO my WP: 0 hasta 4.5.5.3
WordPress · MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO. MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO: 0 hasta 4.2.1
WordPress · WP images upload on piclect
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en WP images upload on piclect. WP images upload on piclect: 0 hasta 1.0
WordPress · wpstorecart
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en wpstorecart. wpstorecart: 0 hasta 5.0.7
WordPress · Album Cover Finder
El registro oficial identifica la vulnerabilidad «CWE-89: SQL Injection» en Album Cover Finder. Album Cover Finder: 0 hasta 0.7.0
WordPress · BEAR
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en BEAR. BEAR: 0 hasta 1.2.2
WordPress · BEAR
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en BEAR. BEAR: 0 hasta 1.2.2
WordPress · BEAR
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en BEAR. BEAR: 0 hasta 1.2.2
WordPress · Custom Menu Wizard Widget
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Custom Menu Wizard Widget. Custom Menu Wizard Widget: 0 hasta 3.3.1
WordPress · Masteriyo LMS
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Masteriyo LMS. Masteriyo LMS: 1.14.0 hasta 3.4.1
WordPress · Masteriyo LMS
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Masteriyo LMS. Masteriyo LMS: 0 hasta 3.4.1
WordPress · Masteriyo LMS
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Masteriyo LMS. Masteriyo LMS: 0 hasta 3.4.1
WordPress · BE REST Endpoints
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en BE REST Endpoints. BE REST Endpoints: 0 hasta 1.0.0
WordPress · Export & Import WPBakery Page Builder
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Export & Import WPBakery Page Builder. Export & Import WPBakery Page Builder: 0 hasta 1.0.2
WordPress · DS Ad Rotator
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en DS Ad Rotator. DS Ad Rotator: 0 hasta 0.8
WordPress · Gpx2Graphics
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Gpx2Graphics. Gpx2Graphics: 0 hasta 0.3
WordPress · Yogeta WP Cloud
El registro oficial identifica la vulnerabilidad «CWE-552: vulnerabilidad de seguridad» en Yogeta WP Cloud. Yogeta WP Cloud: 0 hasta 1.0
WordPress · SAMO Forms
El registro oficial identifica la vulnerabilidad «CWE-89: SQL Injection» en SAMO Forms. SAMO Forms: 0 hasta 1.0.0
WordPress · Tutor LMS – eLearning and online course solution
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 4.0.7
WordPress · The Events Calendar
El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en The Events Calendar. The Events Calendar: 0 hasta 6.17.3
WordPress · SureRank SEO
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en SureRank SEO. SureRank SEO: 1.6.2 hasta 1.10.1
WordPress · The Events Calendar
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en The Events Calendar. The Events Calendar: 0 hasta 6.17.4
WordPress · Temporary Login Without Password
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Temporary Login Without Password. Temporary Login Without Password: 0 hasta 1.9.9
WordPress · Temporary Login Without Password
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Temporary Login Without Password. Temporary Login Without Password: 1.5 hasta 1.9.9
WordPress · Booking for Appointments and Events Calendar
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Booking for Appointments and Events Calendar. Booking for Appointments and Events Calendar: 0 hasta 2.4.10
WordPress · Booking for Appointments and Events Calendar
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Booking for Appointments and Events Calendar. Booking for Appointments and Events Calendar: 9.0 hasta 9.8.1
WordPress · Smart Marketing SMS and Newsletters Forms
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Smart Marketing SMS and Newsletters Forms. Smart Marketing SMS and Newsletters Forms: 0 hasta 5.1.24
WordPress · WebTotem Backups
El registro oficial identifica la vulnerabilidad «CWE-73: vulnerabilidad de seguridad» en WebTotem Backups. WebTotem Backups: 0 hasta 1.0.1
WordPress · CODE MONKEYS PROPOSALS
El registro oficial identifica la vulnerabilidad «CWE-73: vulnerabilidad de seguridad» en CODE MONKEYS PROPOSALS. CODE MONKEYS PROPOSALS: 0 hasta 1.0.1
WordPress · Frontegg SAML SSO
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Frontegg SAML SSO. Frontegg SAML SSO: 0 hasta 1.0.1
WordPress · Royal Addons for Elementor – Addons and Templates Kit for Elementor
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Royal Addons for Elementor – Addons and Templates Kit for Elementor. Royal Addons for Elementor – Addons and Templates Kit for Elementor: 0 hasta 1.7.1066
WordPress · rtMedia for WordPress, BuddyPress and bbPress
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en rtMedia for WordPress, BuddyPress and bbPress. rtMedia for WordPress, BuddyPress and bbPress: 0 hasta 4.7.11
WordPress · MemberPress Corporate Accounts
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en MemberPress Corporate Accounts. MemberPress Corporate Accounts: 0 hasta 1.5.39
WordPress · DT LMS – elearning, WordPress LMS Plugin
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en DT LMS – elearning, WordPress LMS Plugin. DT LMS – elearning, WordPress LMS Plugin: 0 hasta 1.1
WordPress · Booking for Appointments and Events Calendar – Amelia
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Booking for Appointments and Events Calendar – Amelia. Booking for Appointments and Events Calendar – Amelia: 0 hasta 2.4.9
WordPress · MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.. MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.: 0 hasta 1.2.2
WordPress · BackWPup
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en BackWPup. BackWPup: 5.2.2 hasta 5.7.5
WordPress · MetForm
El registro oficial identifica la vulnerabilidad «CWE-93: vulnerabilidad de seguridad» en MetForm. MetForm: 0 hasta 4.1.9
WordPress · WPCafe
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en WPCafe. WPCafe: 3.0.10 hasta 3.0.18
WordPress · Persian Elementor
El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en Persian Elementor. Persian Elementor: 2.7.10 hasta 2.8.2
WordPress · Visualizer
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Visualizer. Visualizer: 4.0.0 hasta 4.0.6
WordPress · SSL Zen — SSL Certificate Installer & HTTPS Redirects
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en SSL Zen — SSL Certificate Installer & HTTPS Redirects. SSL Zen — SSL Certificate Installer & HTTPS Redirects: 0 hasta 4.7.40