Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
01/09/2026
[CVE-2026-10195] The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and incl…
The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to exec…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19513] The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to,…
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This m…
M Crítico vulnerabilidad
01/09/2026
Escalada de privilegios crítica en tema WordPress Nokri - Validación insuficiente de tokens
El tema WordPress Nokri Job Board contiene una vulnerabilidad de escalada de privilegios en versiones hasta 1.6.6 que permite a atacantes no autenticados tomar control de cuentas de usuario. La falla radica en validación deficiente de tokens de reinicio de contraseña en la función `nokri_reset_password()`, que acepta tokens vacíos coincidiendo con valores de metadata desconfigurados. Esto afecta directamente a empresas de LATAM que operan portales de empleo en WordPress, exponiendo bases de datos de candidatos y datos administrativos.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19914] The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cu…
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected paylo…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19573] The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19796] The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vul…
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and including, 5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19806] The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin …
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19952] The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due t…
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-conf…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-75921] The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widge…
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the upload_template_kit() AJAX handler, which requires only upload_files capability instea…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75865] The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode pl…
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82229] Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register
M Alto vulnerabilidad
31/08/2026
[CVE-2026-75133] Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulner…
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable dump filename based on the database name, a limited random range, and the current…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-66047] ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code…
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82607] A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impact…
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.…
M Crítico vulnerabilidad
30/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin MyHome Core para WordPress (CVE-2026-15980)
El plugin MyHome Core para WordPress versiones hasta 4.4.5 contiene una falla crítica (CVSS 9.8) que permite a atacantes no autenticados generar tokens de activación y obtener acceso válido a cuentas de usuario. La vulnerabilidad radica en la ausencia de validación de autorización en el manejador AJAX send_link() y validación inadecuada de tokens en la función activate(). Esta exposición afecta directamente a inmobiliarias, constructoras y empresas de servicios en LATAM que utilizan este plugin en sitios WordPress publicitarios o de gestión de propiedades.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin SAML SSO para WordPress (CVE-2026-75807)
El plugin SAML Single Sign On – SSO Login para WordPress (versiones ≤5.4.6) contiene una vulnerabilidad de elusión de autenticación que permite a atacantes validar certificados X.509 antes de completar la verificación de firma en la respuesta SAML. En LATAM, donde muchas empresas integran WordPress con sistemas de identidad corporativa SAML, esta falla expone credenciales y acceso no autorizado a portales internos, clientes y plataformas e-commerce.
M Crítico vulnerabilidad
29/08/2026
Ejecución Remota de Código en Plugin Sigma Forms Pro para WordPress (CVE-2026-14494)
El plugin Sigma Forms Pro para WordPress (versiones hasta 1.4.5) es vulnerable a ejecución remota de código (RCE) mediante la función handle_form_submission. La vulnerabilidad permite a atacantes no autenticados subir archivos maliciosos al explotar la asignación dinámica de capacidades unfiltered_upload y el bypass de validación de tipos MIME. Afecta directamente a sitios WordPress en LATAM que utilizan este plugin para gestión de formularios sin parches.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76586] The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does no…
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.