Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 932 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
[CVE-2026-86406] The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of t…
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-89080] The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated reques…
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-80071] The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may…
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-15451] The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in ver…
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev…
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin Tutor LMS para WordPress
El plugin Tutor LMS (versiones ≤4.0.7) contiene una vulnerabilidad de inyección de objetos PHP en el manejador AJAX `tutor_save_withdraw_account` que permite a atacantes no autenticados ejecutar código mediante el parámetro `withdraw_method_field`. Afecta principalmente a plataformas de educación en línea y cursos corporativos en LATAM que dependen de este plugin en WordPress. El riesgo es alta (CVSS 8.8) al carecer de validación de capacidades/roles, confiando solo en nonce.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inclusión de archivos locales en plugin GEO my WP para WordPress
El plugin GEO my WP en todas las versiones hasta 4.5.5.3 es vulnerable a Local File Inclusion (LFI) a través de la función gmw_posts_locator_ajax_info_window_loader. Atacantes sin autenticación pueden incluir y ejecutar archivos PHP arbitrarios en el servidor, comprometiendo la integridad del sitio y permitiendo ejecución de código malicioso. Esta vulnerabilidad afecta significativamente a sitios inmobiliarios, directorios y plataformas de ubicación operadas en LATAM.
M Alto vulnerabilidad
12/09/2026
Inyección SQL en plugin rtMedia para WordPress afecta versiones hasta 4.7.11
El plugin rtMedia para WordPress, BuddyPress y bbPress es vulnerable a inyección SQL ciega basada en tiempo a través del parámetro 'compare' en todas las versiones hasta la 4.7.11. Atacantes no autenticados pueden ejecutar consultas SQL adicionales explotando insuficiente validación de entrada. Esta vulnerabilidad afecta especialmente a sitios de medios, redes sociales corporativas y comunidades en línea operadas por empresas mexicanas y latinoamericanas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84099] The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a …
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87759] The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check…
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87842] The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check be…
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87888] The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST rout…
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84047] The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parame…
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77752] The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user req…
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promo…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-80491] The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input befor…
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-80494] The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before …
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81090] The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploa…
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81429] The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF c…
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81742] The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before…
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77705] The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify tha…
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XCS en plugin Kirki para WordPress afecta hasta versión 6.2.0
El plugin Kirki (Freeform Page Builder) para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en el parámetro 'comment' que permite a atacantes no autenticados inyectar scripts maliciosos. La falta de sanitización de entrada y escapado de salida afecta todas las versiones hasta 6.2.0, comprometiendo sitios web de empresas, agencias digitales y plataformas de comercio electrónico en LATAM que utilizan este constructor de páginas.