Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 247 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77005] The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file pa…
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77006] The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, doe…
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-75800] The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML…
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14563] The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before i…
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14559] The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password befo…
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14560] The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded fi…
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-8778] The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for …
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-78361] The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform …
The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed zipMoney…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-77770] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOran…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-18351] The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary Fi…
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via …
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-75816] The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Acco…
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as t…
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-16310] The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over t…
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin Mail Mint para WordPress
El plugin Mail Mint (versiones hasta 1.31.0) para WordPress presenta una vulnerabilidad de inyección de objetos PHP (CVSS 9.8) que permite a atacantes no autenticados ejecutar código arbitrario mediante deserialización de datos no validados en la función 'handle_form_submission'. Afecta principalmente a tiendas WooCommerce y plataformas de email marketing en LATAM que utilizan este plugin.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en plugin ComboBlocks para WordPress permite inyección de hooks sin autenticación
El plugin 'The Post Grid and Gutenberg Blocks – ComboBlocks' en versiones 2.2.32 a 2.3.1 es vulnerable a inyección de hooks no autenticada, permitiendo a atacantes ejecutar acciones maliciosas en WordPress sin credenciales. La vulnerabilidad afecta miles de sitios web en México y LATAM que utilizan este plugin para construcción de contenido con Gutenberg, exponiendo datos y funcionalidades críticas del sitio.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-83627] The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulner…
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leadi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-13447] The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versio…
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-82923] The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n…
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads di…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-15354] The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,…
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-11613] The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-77009] The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console,…
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.