Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 474 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1741
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-3430] The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo…
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66705] Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS Almacenado alta en FormGent para WordPress (CVE-2025-15028)
El plugin FormGent para WordPress es vulnerable a inyección de scripts almacenados (XSS) en campos de formularios hasta la versión 1.9.2 debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta en navegadores de visitantes, comprometiendo datos de formularios y credenciales de clientes. Afecta directamente a pymes y emprendimientos en LATAM que utilizan este plugin para captura de leads, pagos y encuestas.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS almacenado alta en plugin TranslatePress para WordPress (CVE-2026-18510)
El plugin TranslatePress de WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en versiones hasta 3.2.6 que permite a atacantes sin autenticación inyectar código malicioso a través de comentarios con marcadores gettext codificados. La falta de sanitización de entrada y escapado de salida afecta directamente a sitios web multilingües en México y LATAM que dependen de este plugin para traducción de contenidos, comprometiendo la integridad y seguridad de visitantes y datos.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16268] The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r…
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16734] The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call…
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18050] The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST r…
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, s…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13153] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13154] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-suppl…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-14829] The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin throug…
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPres…
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin WPMU DEV Dashboard para WordPress
El plugin WPMU DEV Dashboard para WordPress (versiones hasta 5.0.0) contiene una vulnerabilidad de elusión de autenticación que afecta sitios no conectados al WPMU DEV Hub. La clave API del sitio permanece vacía en la configuración predeterminada, permitiendo falsificar firmas de solicitud WDP-AUTH. Esto expone a empresas mexicanas y latinoamericanas con sitios WordPress multisite a acceso no autorizado a funcionalidades administrativas altas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18325] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16636] The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Pr…
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-15991] The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7529] The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthori…
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-17506] The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …
The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstruc…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-15979] The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable t…
The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directl…
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en plugin wp-downloadmanager permite carga de archivos arbitrarios
El plugin wp-downloadmanager en versiones 1.68.11 y 6.9.4 contiene una vulnerabilidad que permite a usuarios administradores cargar archivos sin validación de extensión ni tipo MIME a través de download-add.php. Esta falla afecta directamente a sitios WordPress en LATAM que dependen de este plugin para gestión de descargas, exponiendo servidores a ejecución de código malicioso y compromisos totales del sitio.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7444] The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7520] The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of …
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMu…