Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 475 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
W Alto vulnerabilidad
21/07/2026
[CVE-2026-63030] Vulnerabilidad explotada activamente en WordPress Core
CISA confirma explotación activa de una vulnerabilidad en WordPress Core. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-24.
M Alto vulnerabilidad
20/07/2026
[CVE-2026-9833] The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does…
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into follow…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-12970] The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting i…
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.
M Alto vulnerabilidad
20/07/2026
[CVE-2026-13142] The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce r…
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, …
M Alto vulnerabilidad
20/07/2026
[CVE-2026-11349] The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress …
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.
M Alto vulnerabilidad
20/07/2026
[CVE-2026-12592] The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocatio…
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured t…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-10081] The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Goog…
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/07/2026
[CVE-2026-11575] The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticit…
The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-11961] The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the members…
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exis…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-13765] The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul…
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including …
M Alto vulnerabilidad
17/07/2026
[CVE-2026-13352] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C…
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the …
M Alto vulnerabilidad
17/07/2026
[CVE-2026-15395] The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored C…
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an …
M Alto vulnerabilidad
16/07/2026
[CVE-2026-7543] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' pa…
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15005] The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses …
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15008] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for …
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15103] The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress…
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_op…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13741] The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege…
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administr…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12585] The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity…
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12978] The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before ref…
The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12525] The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri…
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) fe…