Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 38 min
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87771] The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape paramete…
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87774] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87775] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81810] The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability…
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the expor…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84738] The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through…
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85122] The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted va…
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-17086] The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulner…
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54239] Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticate…
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86801] The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does n…
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files alread…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87963] The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username reques…
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-88795] The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authenticat…
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88904] The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST rou…
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-91014] The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise an…
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86707] The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate …
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86709] The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session …
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86710] The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in…
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87786] The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at che…
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88792] The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in…
The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
M Alto vulnerabilidad
17/09/2026
[CVE-2025-15697] The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in …
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…