Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "WordPress" — 932 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18946] The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copyin…
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17022] The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's o…
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17541] The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST…
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17542] The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its f…
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-14206] The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the e…
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16041] The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership …
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16262] The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login fl…
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16263] The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX ac…
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16030] The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature…
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-15215] The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capabilit…
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) t…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-15361] The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJA…
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-14943] The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress p…
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed i…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16619] The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-facto…
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16620] The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-si…
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfi…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-12584] The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the …
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13399] The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper autho…
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10524] The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the a…
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10599] The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verif…
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-3430] The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo…
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66705] Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress