Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-104899] The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPre…
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. Thi…
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-94067] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio…
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-94062] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio…
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through 4.8.3.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad alta de inclusión de archivos en plugin WPCafe para WordPress
El plugin WPCafe para WordPress (versiones hasta 3.0.18) contiene una vulnerabilidad de Local File Inclusion (LFI) que permite a usuarios con acceso de colaborador o superior ejecutar archivos PHP arbitrarios en el servidor. Esta vulnerabilidad afecta directamente a restaurantes, cafeterías y negocios de alimentos en LATAM que utilizan este plugin para sistemas de pedidos en línea y reservas de mesas, comprometiendo la integridad del sitio web y datos de clientes.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-92174] The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all vers…
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to by…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96837] Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
Contributor Remote Code Execution (RCE) in CartFlows
M Alto vulnerabilidad
30/09/2026
[CVE-2026-89294] The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all v…
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-49850] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads attacker-controlled content that requests an affected route, the application can delete an…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-50547] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting PHP path without validating the identifier. A low-privileged attacker who can influence the e-invoice configuration can use traversal sequenc…
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad de Inclusión de Archivos Locales en Plugin WP Maps para WordPress
El plugin WP Maps (versiones hasta 4.9.8) presenta una vulnerabilidad de Local File Inclusion (LFI) que permite a atacantes autenticados con acceso de suscriptor ejecutar archivos PHP arbitrarios en el servidor mediante el parámetro 'page'. Esta falla afecta directamente a sitios WordPress que utilizan este plugin en México y LATAM para gestionar ubicaciones de tiendas y directorios, comprometiendo la integridad del servidor y acceso a datos sensibles.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87902] An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen…
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de inclusión de archivos en WP Travel Engine hasta v6.8.0
El plugin WP Travel Engine para WordPress es vulnerable a Local File Inclusion (LFI) en versiones anteriores a 6.8.0, permitiendo a atacantes autenticados con acceso de colaborador ejecutar archivos PHP arbitrarios en el servidor. Esta vulnerabilidad afecta directamente a agencias de viajes y operadores turísticos en LATAM que utilizan WordPress para gestionar reservas y consultas de tours, comprometiendo la integridad del servidor y datos de clientes.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de inclusión de archivos en plugin HUSKY Products Filter para WooCommerce
El plugin HUSKY – Products Filter for WooCommerce Professional para WordPress (versiones hasta 1.4.4) contiene una vulnerabilidad de Local File Inclusion (LFI) que permite a atacantes no autenticados ejecutar código PHP arbitrario en servidores. Esta falla afecta directamente a tiendas en línea de LATAM que usan este plugin, exponiendo bases de datos, credenciales y datos de clientes. Con CVSS 8.1, es considerada alta y requiere acción inmediata.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27555] A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/…
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27556] A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/…
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inclusión de archivos locales en plugin GEO my WP para WordPress
El plugin GEO my WP en todas las versiones hasta 4.5.5.3 es vulnerable a Local File Inclusion (LFI) a través de la función gmw_posts_locator_ajax_info_window_loader. Atacantes sin autenticación pueden incluir y ejecutar archivos PHP arbitrarios en el servidor, comprometiendo la integridad del sitio y permitiendo ejecución de código malicioso. Esta vulnerabilidad afecta significativamente a sitios inmobiliarios, directorios y plataformas de ubicación operadas en LATAM.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87927] MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxs…
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-15406] The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPres…
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution o…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-15667] The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPres…
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78562] The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a…
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and …