Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1155 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-101148] The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its …
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The Backu…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101147] The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Pre…
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF at…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-92966] The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for Word…
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96561] The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to …
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task (Meow_MWAI_Modules_Advis…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92245] The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposur…
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment publ…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97197] Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Unauthenticated Broken Access Control in WordPress Backup & Migration
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94081] Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-93512] Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta de Directory Traversal en Plugin Product Designer App para WordPress (CVE-2026-75098)
El plugin Product Designer App para WordPress en versiones hasta 1.1.3 es vulnerable a Directory Traversal a través del parámetro 'svg', permitiendo a atacantes no autenticados leer archivos arbitrarios del servidor. Esta vulnerabilidad expone información sensible como credenciales de bases de datos, archivos de configuración y datos de usuarios en tiendas virtuales y sitios corporativos. El ataque requiere solo acceso a internet sin credenciales válidas, representando riesgo alta para e-commerce y plataformas en LATAM.
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad XSS almacenado alta en plugin Post Views Stats Counter para WordPress
El plugin Post Views Stats Counter de WordPress es vulnerable a inyección de scripts almacenados (Stored XSS) a través del encabezado User-Agent en versiones hasta la 1.1.7, permitiendo a atacantes no autenticados ejecutar código malicioso en páginas que afecta a todos los visitantes. Esta vulnerabilidad representa alto riesgo para sitios web de empresas, organismos públicos y plataformas de comercio electrónico en LATAM que utilicen este plugin sin actualizar.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-6806] The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-…
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additio…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-89294] The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all v…
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-91832] The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings …
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92994] The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents …
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-89193] The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTM…
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-88797] The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX act…
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-85573] The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload typ…
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-75873] The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one o…
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-75823] The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned …
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96649] The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress i…
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…