Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "WordPress" — 932 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad XSS almacenado alta en plugin WP Yelp Review Slider (CVE-2026-93778)
El plugin WP Yelp Review Slider para WordPress en versiones hasta 9.2 presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar scripts maliciosos a través del texto de reseñas de Yelp importadas. La falta de sanitización de entrada y escapado de salida permite que estos scripts se ejecuten cuando usuarios acceden a páginas comprometidas, afectando potencialmente datos sensibles y sesiones de administradores en sitios WordPress de empresas en LATAM.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad XSS almacenado en WPC Product Bundles for WooCommerce (CVE-2026-93836)
El plugin WPC Product Bundles para WooCommerce contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'qty' en versiones hasta 8.6.6, permitiendo a atacantes no autenticados inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas. Afecta tiendas en línea y plataformas de comercio electrónico en LATAM que utilizan WooCommerce. CVSS 7.2 (alto).
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta en plugin WP Ultimate Review permite ejecución arbitraria de shortcodes
El plugin WP Ultimate Review para WordPress (versiones hasta 2.4.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en acciones de usuario. Atacantes autenticados con acceso de suscriptor pueden ejecutar código arbitrario, comprometiendo sitios WordPress comúnmente usados en LATAM para ecommerce, contenido corporativo y aplicaciones altas.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de inclusión de archivos en plugin HUSKY Products Filter para WooCommerce
El plugin HUSKY – Products Filter for WooCommerce Professional para WordPress (versiones hasta 1.4.4) contiene una vulnerabilidad de Local File Inclusion (LFI) que permite a atacantes no autenticados ejecutar código PHP arbitrario en servidores. Esta falla afecta directamente a tiendas en línea de LATAM que usan este plugin, exponiendo bases de datos, credenciales y datos de clientes. Con CVSS 8.1, es considerada alta y requiere acción inmediata.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-6922] The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Aut…
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never fire, combined with a permission callback that only verifies plugin role membership…
M Alto vulnerabilidad
22/09/2026
[CVE-2025-1281] The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic…
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-91827] The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being…
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-92438] The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputtin…
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94504] Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encod…
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-89412] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-12470] The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unau…
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrar…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92540] The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce t…
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92541] The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote…
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-82842] The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for …
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-85017] The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability ch…
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87839] The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate…
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-81650] The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate…
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that exec…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de exposición de datos en plugin YS LeadGen para WordPress (CVE-2026-1255)
El plugin YS LeadGen para WordPress en versiones hasta 2.1.4 expone datos sensibles de formularios a usuarios no autenticados a través de la acción AJAX 'ysleadgen_get_captured_data'. Atacantes pueden acceder a información personal (nombres, correos, teléfonos) recopilada en formularios de contacto y generación de leads, afectando sitios web corporativos y de marketing en LATAM. El score CVSS 7.5 indica riesgo alto para empresas que dependen de este plugin.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución de shortcodes en ProfilePress para WordPress
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.