Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de XSS almacenado en plugin Contact Form by Supsystic para WordPress
El plugin Contact Form by Supsystic (versiones hasta 1.10.2) contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar código malicioso a través del encabezado de dirección IP. Esto afecta a miles de sitios WordPress en LATAM que usan este plugin, exponiendo datos de usuarios y permitiendo comprometer la integridad de formularios de contacto. La vulnerabilidad tiene CVSS 7.2, indicando riesgo alto para empresas que recopilan información sensible a través de estos formularios.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-77830] The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored C…
The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that …
M Alto vulnerabilidad
05/09/2026
[CVE-2026-78438] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con…
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Thi…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-18406] The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is …
The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19769] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to…
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19887] The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-15984] The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Para…
The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce guarding the unauthenti…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/09/2026
[CVE-2026-16649] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Fi…
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time…
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-83627] The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulner…
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leadi…
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-13447] The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versio…
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-77233] The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vu…
The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-77263] The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vu…
The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesse…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-12483] The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up…
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled …
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-82923] The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n…
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads di…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-15354] The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,…
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-16281] The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can ed…
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19224] The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting…
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-11613] The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-77009] The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console,…
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-4357] The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files vi…
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.