Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución remota de código en plugin WP Photo Album Plus para WordPress
El plugin WP Photo Album Plus para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones debido a sanitización insuficiente en nombres de archivo cargados. La vulnerabilidad reside en la función wppa_image_magick, donde escapeshellcmd() se aplica al comando completo en lugar de entrecomillar argumentos individuales antes de ejecutar comandos ImageMagick via exec(). Esto afecta directamente a sitios WordPress en México y Latinoamérica que dependen de este plugin para galerías de fotos.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XSS almacenado en plugin Asset CleanUp para WordPress afecta versiones hasta 1.4.0.5
El plugin Asset CleanUp: Page Speed Booster para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar scripts maliciosos a través de comentarios. Los scripts se ejecutan cuando usuarios acceden a páginas comprometidas, afectando sitios web en México y Latinoamérica que utilizan este plugin para optimización de velocidad. Con CVSS 7.2, representa un riesgo alto para plataformas de comercio electrónico, portales corporativos y blogs que dependen de WordPress.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93031] The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordP…
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported f…
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad XPS almacenado en Popup Maker para WordPress afecta versiones hasta 1.24.0
El plugin Popup Maker para WordPress es vulnerable a inyección de scripts (XSS almacenado) en el parámetro values[Name] hasta la versión 1.24.0, permitiendo que atacantes sin autenticación inyecten código malicioso en páginas públicas. Esta vulnerabilidad (CVSS 7.2) afecta directamente a tiendas en línea y sitios de generación de leads en LATAM que usan este plugin para captura de datos.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de Cross-Site Scripting Almacenado en Jeg Kit for Elementor hasta v3.2.16
El plugin Jeg Kit for Elementor para WordPress contiene una vulnerabilidad de Stored XSS (CVSS 7.2) que permite a atacantes no autenticados inyectar scripts maliciosos a través de contenido de comentarios. Los scripts se ejecutan cuando otros usuarios acceden a las páginas afectadas, comprometiendo datos de visitantes y administradores. Afecta todas las versiones hasta la 3.2.16, siendo alta en sitios de e-commerce y portales corporativos comunes en LATAM.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad XSS Almacenado en plugin Complianz GDPR/CCPA para WordPress (CVE-2026-83561)
El plugin Complianz GDPR/CCPA Cookie Consent Banner para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en versiones hasta la 7.5.4. Atacantes no autenticados pueden inyectar scripts maliciosos a través del contenido de comentarios usando la expresión regular del bloqueador de cookies de Elementor. La falla resulta de validación insuficiente de entrada y escape inadecuado de salida. Empresas en México y LATAM que usen este plugin están en riesgo de comprometimiento de datos de visitantes y sesiones de usuarios.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de elusión de autorización en Master Addons for Elementor hasta v3.2.2
El plugin Master Addons for Elementor para WordPress es vulnerable a elusión de autorización en todas las versiones hasta la 3.2.2, permitiendo que atacantes autenticados con rol de colaborador ejecuten acciones no autorizadas. Esta vulnerabilidad afecta especialmente a agencias web, diseñadores freelance y empresas en LATAM que utilizan Elementor para gestionar sitios corporativos. Con CVSS 8.1, representa un riesgo alto para la integridad y confidencialidad del contenido.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85705] The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and …
The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already ex…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-18442] The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to…
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append add…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-12954] The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions …
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-14323] The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Di…
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-15275] The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the '…
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89413] The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to,…
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-92619] The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up t…
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassi…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93485] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88825] The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearan…
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-90978] The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX ha…
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85127] The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type …
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87767] The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and es…
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87770] The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape para…
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.