Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1155 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87741] The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versi…
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed …
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96896] The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perfor…
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-86609] The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted throu…
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-81655] The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its set…
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-82901] The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due …
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-85984] The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-77203] The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalati…
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96524] The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress …
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96532] The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership ch…
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
M Crítico vulnerabilidad
26/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin Request a Quote for WooCommerce
El plugin Request a Quote for WooCommerce para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta la 2.9.2 debido a validación insuficiente de extensiones y tipos MIME en la función afrfq_submit_quote_via_popup(). Un atacante puede cargar archivos maliciosos (como shells PHP) directamente al servidor sin restricción, comprometiendo completamente sitios de comercio electrónico en LATAM. Con CVSS 9.8, afecta principalmente a pequeñas y medianas empresas que usan este plugin para gestionar cotizaciones de productos.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84095] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84096] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-85081] The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File M…
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary J…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-16591] The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category…
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affect…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Repeater Fields para Elementor Forms (CVE-2026-94573)
El plugin Repeater Fields for Elementor Forms en WordPress (versiones hasta 2.2.7) contiene una falla de validación que permite a atacantes sin autenticación inyectar scripts maliciosos en formularios. Los scripts ejecutados afectan a todos los usuarios que accedan a páginas con formularios comprometidos, comprometiendo datos sensibles en sitios empresariales y de e-commerce. Este riesgo es alta para organizaciones en LATAM que usan Elementor como constructor de sitios.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSD alta en Themify Builder para WordPress afecta sitios sin autenticación
El plugin Themify Builder para WordPress (versiones hasta 7.8.1) es vulnerable a inyección de scripts almacenados (Stored XSS) a través del parámetro 'css[fonts]' sin validación adecuada. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas, comprometiendo datos de administradores y visitantes en sitios empresariales de México y LATAM que usen este plugin.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XLS almacenado en User Profile Builder para WordPress (CVE-2026-95866)
El plugin User Profile Builder para WordPress es vulnerable a inyección de scripts entre sitios (XLS) a través del campo de avatar en versiones hasta 4.0.2. Atacantes no autenticados pueden ejecutar código malicioso en páginas del sitio afectando a todos los visitantes. El riesgo es alta en sitios con registro público de usuarios.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Restaurant Menu and Food Ordering para WordPress (CVE-2026-96568)
El plugin Restaurant Menu and Food Ordering para WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'phone_number' hasta la versión 2.4.14, permitiendo a atacantes no autenticados inyectar scripts maliciosos que se ejecutan cuando usuarios visitan páginas comprometidas. Afecta principalmente a restaurantes, bares y negocios de comida en línea en LATAM que usan este plugin, exponiendo datos de clientes y comprometiendo la integridad de transacciones. Con CVSS 7.2, representa un riesgo considerable para plataformas de pedidos online.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Zero Spam para WordPress (CVE-2026-96752)
El plugin Zero Spam para WordPress es vulnerable a inyección de scripts maliciosos (XSS almacenado) en versiones hasta 5.7.10 mediante arrays POST anidados en integración con Contact Form 7. Atacantes no autenticados pueden ejecutar código JavaScript en páginas públicas cuando usuarios acceden a formularios comprometidos, afectando sitios empresariales, tiendas en línea y portales de atención al cliente en México y LATAM que usen este plugin.