Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "WordPress" — 932 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-12954] The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions …
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-14323] The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Di…
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-15275] The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the '…
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89413] The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to,…
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-92619] The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up t…
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassi…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93485] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88825] The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearan…
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-90978] The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX ha…
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85127] The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type …
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87767] The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and es…
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87770] The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape para…
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87771] The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape paramete…
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87774] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87775] The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter…
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81810] The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability…
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the expor…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85122] The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted va…
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-17086] The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulner…
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54239] Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticate…
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86801] The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does n…
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files alread…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87963] The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username reques…
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.