Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad XMS almacenado alta en plugin Transliterator para WordPress
El plugin The Transliterator (versiones hasta 2.5.8) para WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar código malicioso a través de comentarios. La falla radica en insuficiente sanitización de entrada y escapado de salida en placeholders predecibles {rstr_keep}. Afecta directamente a sitios WordPress en LATAM con comentarios públicos habilitados, exponiendo datos de visitantes y administradores.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad XLS almacenado en GD Rating System para WordPress afecta sitios sin autenticación
El plugin GD Rating System (versiones ≤3.7.1) contiene un fallo de validación en los parámetros 'title' y 'url' del manejador AJAX gdrts_live_handler, permitiendo inyección de scripts maliciosos sin requerir autenticación. Los atacantes pueden ejecutar código arbitrario en el navegador de visitantes, comprometiendo sesiones administrativas, robando credenciales o redirigiendo tráfico. Afecta especialmente a sitios de e-commerce y plataformas de opiniones en LATAM.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-88783] The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed H…
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administr…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-87091] The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlem…
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The IPN endp…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-101928] The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script…
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is p…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-101159] The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews s…
The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.
M Alto vulnerabilidad
03/10/2026
[CVE-2026-92977] The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored …
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Maliciou…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/10/2026
[CVE-2026-96270] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem…
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-93875] The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friend…
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload …
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad SSRF alta en YesWiki anterior a 4.6.7 permite inyección de código
YesWiki versiones anteriores a 4.6.7 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la acción Bazar valeur que permite a editores de páginas forzar al servidor a acceder URLs arbitrarias. Los atacantes pueden explotar esta falla para escanear servicios internos, acceder a metadatos de instancias en la nube (AWS/Azure) y ejecutar scripts maliciosos en navegadores de usuarios. El impacto es alta para wikis colaborativos en instituciones educativas y gubernamentales de LATAM.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104414] Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows atta…
Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104411] Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows sta…
Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff users' admin sessions.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104413] Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows sta…
Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-87920] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con…
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Thi…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97663] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This require…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97342] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97641] The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploita…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96566] The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cro…
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injec…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96567] The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' p…
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The CSRF gate protecting form su…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96578] The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross…
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This…