Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 49 de 70

Media

WordPress · Institute Management – Learning Management System

CVE-2026-2714: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Institute Management – Learning Management System

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Institute Management – Learning Management System. Institute Management – Learning Management System: 0 hasta 5.5

Leer análisis
Media

WordPress · wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin

CVE-2026-5721: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin. wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin: 0 hasta 6.5.0.4

Leer análisis
Alta

WordPress · Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder

CVE-2026-5478: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder. Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: 0 hasta 3.4.4

Leer análisis
Media

WordPress · Image Source Control Lite – Show Image Credits and Captions

CVE-2026-4852: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Image Source Control Lite – Show Image Credits and Captions

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Image Source Control Lite – Show Image Credits and Captions. Image Source Control Lite – Show Image Credits and Captions: 0 hasta 3.9.1

Leer análisis
Media

WordPress · EMC – Easily Embed Calendly Scheduling

CVE-2026-0868: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en EMC – Easily Embed Calendly Scheduling

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en EMC – Easily Embed Calendly Scheduling. EMC – Easily Embed Calendly Scheduling: 0 hasta 4.4

Leer análisis
Media

WordPress · Page Builder Gutenberg Blocks – CoBlocks

CVE-2026-4801: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Page Builder Gutenberg Blocks – CoBlocks

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Page Builder Gutenberg Blocks – CoBlocks. Page Builder Gutenberg Blocks – CoBlocks: 0 hasta 3.1.16

Leer análisis
Media

WordPress · Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress

CVE-2026-1559: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress. Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: 0 hasta 1.3.6

Leer análisis
Crítica

WordPress · Accordion and Accordion Slider / Portfolio and Projects / Featured Post Creative

CVE-2026-6443: CWE-506: vulnerabilidad de seguridad en Accordion and Accordion Slider / Portfolio and Projects / Featured Post Creative

El registro oficial identifica la vulnerabilidad «CWE-506: vulnerabilidad de seguridad» en Accordion and Accordion Slider / Portfolio and Projects / Featured Post Creative. Accordion and Accordion Slider: 1.4.6; Portfolio and Projects: 1.5.6; Featured Post Creative: 1.5.7; Post grid and filter ultimate: 1.7.4; WP Featured Content and Slider: 1.7.6; Post Ticker Ultimate: 1.7.6; Trending/Popular Post Slider and Widget: 1.8.6; Meta Slider and Carousel with Lightbox: 2.0.8

Leer análisis
Media

WordPress · Tutor LMS – eLearning and online course solution

CVE-2026-6080: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Tutor LMS – eLearning and online course solution

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tutor LMS – eLearning and online course solution. Tutor LMS – eLearning and online course solution: 0 hasta 3.9.8

Leer análisis
Alta

WordPress · Drag and Drop Multiple File Upload for Contact Form 7

CVE-2026-5710: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Drag and Drop Multiple File Upload for Contact Form 7

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Drag and Drop Multiple File Upload for Contact Form 7. Drag and Drop Multiple File Upload for Contact Form 7: 0 hasta 1.3.9.6

Leer análisis
Media

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-5234: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.3.2

Leer análisis
Alta

WordPress · WP Statistics – Simple, privacy-friendly Google Analytics alternative

CVE-2026-5231: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Statistics – Simple, privacy-friendly Google Analytics alternative

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Statistics – Simple, privacy-friendly Google Analytics alternative. WP Statistics – Simple, privacy-friendly Google Analytics alternative: 0 hasta 14.16.4

Leer análisis
Media

WordPress · Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-5162: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Royal Addons for Elementor – Addons and Templates Kit for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Royal Addons for Elementor – Addons and Templates Kit for Elementor. Royal Addons for Elementor – Addons and Templates Kit for Elementor: 0 hasta 1.7.1056

Leer análisis
Media

WordPress · MasterStudy LMS WordPress Plugin – for Online Courses and Education

CVE-2026-4817: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en MasterStudy LMS WordPress Plugin – for Online Courses and Education

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en MasterStudy LMS WordPress Plugin – for Online Courses and Education. MasterStudy LMS WordPress Plugin – for Online Courses and Education: 0 hasta 3.7.25

Leer análisis
Media

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-3330: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.40

Leer análisis
Media

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-4160: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 6.1.21

Leer análisis
Media

WordPress · Shortcodes Ultimate – Content Elements

CVE-2026-3885: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Shortcodes Ultimate – Content Elements

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Shortcodes Ultimate – Content Elements. Shortcodes Ultimate – Content Elements: 0 hasta 7.4.9

Leer análisis
Media

WordPress · BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor

CVE-2026-3875: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor. BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor: 0 hasta 4.3.8

Leer análisis
Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-3614: CWE-862: Falta de autorización en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 9.11.0 hasta 10.8.1

Leer análisis
Alta

WordPress · DirectoryPress – Business Directory And Classified Ad Listing

CVE-2026-3489: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en DirectoryPress – Business Directory And Classified Ad Listing

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en DirectoryPress – Business Directory And Classified Ad Listing. DirectoryPress – Business Directory And Classified Ad Listing: 0 hasta 3.6.26

Leer análisis
Media

WordPress · Better Find and Replace – AI-Powered Suggestions

CVE-2026-3369: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Better Find and Replace – AI-Powered Suggestions

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Better Find and Replace – AI-Powered Suggestions. Better Find and Replace – AI-Powered Suggestions: 0 hasta 1.7.9

Leer análisis
Media

WordPress · Email Encoder – Protect Email Addresses and Phone Numbers

CVE-2026-2840: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Email Encoder – Protect Email Addresses and Phone Numbers

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Email Encoder – Protect Email Addresses and Phone Numbers. Email Encoder – Protect Email Addresses and Phone Numbers: 0 hasta 2.4.4

Leer análisis