Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 5 de 70

Alta

WordPress · Simple Ajax Chat – Add a Fast, Secure Chat Box

CVE-2026-81825: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Simple Ajax Chat – Add a Fast, Secure Chat Box

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Simple Ajax Chat – Add a Fast, Secure Chat Box. Simple Ajax Chat – Add a Fast, Secure Chat Box: 0 hasta 20260811

Leer análisis
Alta

WordPress · Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…

CVE-2026-81754: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…. Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…: 0 hasta 2.10.2

Leer análisis
Media

WordPress · Themify – WooCommerce Product Filter

CVE-2026-78172: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Themify – WooCommerce Product Filter

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Themify – WooCommerce Product Filter. Themify – WooCommerce Product Filter: 0 hasta 1.5.5

Leer análisis
Alta

WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

CVE-2026-19991: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.70

Leer análisis
Media

WordPress · Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty

CVE-2026-18964: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty. Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty: 0 hasta 3.5.9

Leer análisis
Media

WordPress · HUSKY – Products Filter for WooCommerce Professional

CVE-2026-18562: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en HUSKY – Products Filter for WooCommerce Professional

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en HUSKY – Products Filter for WooCommerce Professional. HUSKY – Products Filter for WooCommerce Professional: 0 hasta 1.4.3

Leer análisis
Alta

WordPress · Kirki – Freeform Page Builder, Website Builder & Customizer

CVE-2026-17037: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Kirki – Freeform Page Builder, Website Builder & Customizer

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Kirki – Freeform Page Builder, Website Builder & Customizer. Kirki – Freeform Page Builder, Website Builder & Customizer: 0 hasta 6.2.0

Leer análisis
Alta

WordPress · Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons

CVE-2026-15462: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons. Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons: 0 hasta 1.4.2

Leer análisis
Media

WordPress · GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI

CVE-2026-15439: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI. GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI: 0 hasta 7.9.7

Leer análisis
Media

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-85645: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.46

Leer análisis
Alta

WordPress · Advanced Product Fields Extended for WooCommerce

CVE-2026-81789: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Advanced Product Fields Extended for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Advanced Product Fields Extended for WooCommerce. Advanced Product Fields Extended for WooCommerce: n/a hasta 3.1.6

Leer análisis
Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-77807: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 11.0.4

Leer análisis