Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 474 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
M Alto vulnerabilidad
05/08/2026
[CVE-2026-8761] The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl…
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` c…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18322] The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versi…
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected a…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-15918] VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injec…
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arb…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16143] The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cr…
The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_t…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-16623] The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before…
The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-16572] The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie …
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-16539] The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value be…
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/08/2026
Vulnerabilidad alta de Directory Traversal en plugin CubeWP Framework para WordPress (CVE-2026-13339)
El plugin CubeWP Framework para WordPress (versiones hasta 1.1.30) contiene una vulnerabilidad de traversal de directorios en la función 'cubewp_get_svg_content' que permite a atacantes sin autenticación leer archivos arbitrarios del servidor, incluyendo credenciales de bases de datos y configuraciones sensibles. Esta vulnerabilidad afecta especialmente a sitios de e-commerce y empresariales en LATAM que utilizan este framework para gestión de contenido. Con puntuación CVSS 7.5, representa un riesgo alto para la confidencialidad de datos corporativos.
M Alto vulnerabilidad
02/08/2026
CVE-2026-18352: Vulnerabilidad alta de Directory Traversal en User Access Manager para WordPress
El plugin User Access Manager para WordPress presenta una vulnerabilidad de recorrido de directorios (Directory Traversal) en todas las versiones hasta la 2.3.15, permitiendo a atacantes no autenticados leer archivos arbitrarios del servidor a través del parámetro 'uamgetfile'. Esta falla expone datos sensibles como configuraciones de base de datos, credenciales y archivos de configuración. Afecta principalmente a sitios WordPress en México y Latinoamérica que utilizan este plugin para gestionar permisos de acceso.
M Alto vulnerabilidad
01/08/2026
[CVE-2026-16144] The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote C…
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This …
M Alto vulnerabilidad
01/08/2026
[CVE-2026-16635] The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a…
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic…
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15450] The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file de…
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX han…
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15052] The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vul…
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesse…
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15988] The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to …
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba…
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15006] The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin f…
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15414] The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in vers…
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15258] The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise a…
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-16236] The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up …
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14930] The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or owners…
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15048] The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its A…
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.