Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1155 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-91827] The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being…
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-92438] The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputtin…
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94504] Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encod…
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-89412] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-12470] The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unau…
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrar…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-19658] The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-13355] The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in vers…
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-82187] The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extens…
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92540] The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce t…
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92541] The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote…
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-82842] The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for …
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-85017] The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability ch…
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87839] The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate…
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de exposición de datos en plugin YS LeadGen para WordPress (CVE-2026-1255)
El plugin YS LeadGen para WordPress en versiones hasta 2.1.4 expone datos sensibles de formularios a usuarios no autenticados a través de la acción AJAX 'ysleadgen_get_captured_data'. Atacantes pueden acceder a información personal (nombres, correos, teléfonos) recopilada en formularios de contacto y generación de leads, afectando sitios web corporativos y de marketing en LATAM. El score CVSS 7.5 indica riesgo alto para empresas que dependen de este plugin.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución de shortcodes en ProfilePress para WordPress
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.
M Alto vulnerabilidad
19/09/2026
Ejecución Remota de Código en plugin Welcomizer para WordPress (CVE-2026-4327)
El plugin Welcomizer para WordPress en versiones hasta 2.8.1 permite ejecución remota de código sin autenticación. La vulnerabilidad CVSS 8.8 se debe a verificación insuficiente de permisos en el manejador AJAX 'savesection' combinado con uso de eval(). Afecta directamente a sitios WordPress en México y LATAM que ejecuten este plugin sin parchear.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XLS almacenado en plugin Quill Forms para WordPress (CVE-2026-15664)
El plugin Quill Forms versiones hasta 5.7.1 es vulnerable a inyección de scripts maliciosos (XLS) a través del campo 'Other' en formularios de opción múltiple, afectando sitios WordPress sin autenticación requerida. Atacantes pueden ejecutar código JavaScript arbitrario en navegadores de usuarios visitantes, comprometiendo datos sensibles en formularios de encuestas y cuestionarios. Impacta principalmente a sitios de comercio electrónico, educación y servicios financieros en LATAM que utilizan este plugin para recolectar información de clientes.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-86591] The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its…
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si…