Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades de WordPress

6.969 registros, ordenados por fecha oficial de publicación descendente.

Mostrando 100 registros · Página 52 de 70

Media

WordPress · Columns by BestWebSoft – Additional Columns Plugin for Posts Pages and Widgets

CVE-2026-3618: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Columns by BestWebSoft – Additional Columns Plugin for Posts Pages and Widgets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Columns by BestWebSoft – Additional Columns Plugin for Posts Pages and Widgets. Columns by BestWebSoft – Additional Columns Plugin for Posts Pages and Widgets: 0 hasta 1.0.3

Leer análisis
Media

WordPress · TableOn – WordPress Posts Table Filterable

CVE-2026-3513: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en TableOn – WordPress Posts Table Filterable

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en TableOn – WordPress Posts Table Filterable. TableOn – WordPress Posts Table Filterable: 0 hasta 1.0.4.4

Leer análisis
Alta

WordPress · Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce

CVE-2026-3499: CWE-352: vulnerabilidad de seguridad en Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce. Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce: 13.4.6 hasta 13.5.2.1

Leer análisis
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-3311: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.9

Leer análisis
Crítica

WordPress · Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder

CVE-2026-3296: CWE-502: Deserialización de datos no confiables en Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder

El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder. Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: 0 hasta 3.4.3

Leer análisis
Media

WordPress · Pinterest Site Verification plugin using Meta Tag

CVE-2026-3142: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Pinterest Site Verification plugin using Meta Tag

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Pinterest Site Verification plugin using Meta Tag. Pinterest Site Verification plugin using Meta Tag: 0 hasta 1.8

Leer análisis
Media

WordPress · PowerPress Podcasting plugin by Blubrry

CVE-2026-2988: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en PowerPress Podcasting plugin by Blubrry

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en PowerPress Podcasting plugin by Blubrry. PowerPress Podcasting plugin by Blubrry: 0 hasta 11.15.15

Leer análisis
Media

WordPress · Page Builder: Pagelayer – Drag and Drop website builder

CVE-2026-2509: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Page Builder: Pagelayer – Drag and Drop website builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Page Builder: Pagelayer – Drag and Drop website builder. Page Builder: Pagelayer – Drag and Drop website builder: 0 hasta 2.0.8

Leer análisis
Media

WordPress · Beaver Builder Page Builder – Drag and Drop Website Builder

CVE-2026-2481: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Beaver Builder Page Builder – Drag and Drop Website Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Beaver Builder Page Builder – Drag and Drop Website Builder. Beaver Builder Page Builder – Drag and Drop Website Builder: 0 hasta 2.10.1.1

Leer análisis
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1865: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.2

Leer análisis
Media

WordPress · BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net

CVE-2026-1673: CWE-352: vulnerabilidad de seguridad en BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net. BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: 0 hasta 1.1.5

Leer análisis
Media

WordPress · BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net

CVE-2026-1672: CWE-352: vulnerabilidad de seguridad en BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net. BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: 0 hasta 1.1.5

Leer análisis
Alta

WordPress · Booking for Appointments and Events Calendar – Amelia

CVE-2026-5465: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Booking for Appointments and Events Calendar – Amelia

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Booking for Appointments and Events Calendar – Amelia. Booking for Appointments and Events Calendar – Amelia: 0 hasta 2.1.3

Leer análisis