Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "WordPress" — 242 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75865] The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode pl…
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker…
M Crítico vulnerabilidad
30/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin MyHome Core para WordPress (CVE-2026-15980)
El plugin MyHome Core para WordPress versiones hasta 4.4.5 contiene una falla crítica (CVSS 9.8) que permite a atacantes no autenticados generar tokens de activación y obtener acceso válido a cuentas de usuario. La vulnerabilidad radica en la ausencia de validación de autorización en el manejador AJAX send_link() y validación inadecuada de tokens en la función activate(). Esta exposición afecta directamente a inmobiliarias, constructoras y empresas de servicios en LATAM que utilizan este plugin en sitios WordPress publicitarios o de gestión de propiedades.
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.
M Crítico vulnerabilidad
29/08/2026
Ejecución Remota de Código en Plugin Sigma Forms Pro para WordPress (CVE-2026-14494)
El plugin Sigma Forms Pro para WordPress (versiones hasta 1.4.5) es vulnerable a ejecución remota de código (RCE) mediante la función handle_form_submission. La vulnerabilidad permite a atacantes no autenticados subir archivos maliciosos al explotar la asignación dinámica de capacidades unfiltered_upload y el bypass de validación de tipos MIME. Afecta directamente a sitios WordPress en LATAM que utilizan este plugin para gestión de formularios sin parches.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76581] The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions u…
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-19092] The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal …
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
M Crítico vulnerabilidad
27/08/2026
Inyección SQL sin autenticación en Beautiful Taxonomy Filters <= 2.4.6
Se ha identificado una vulnerabilidad crítica de inyección SQL sin autenticación en Beautiful Taxonomy Filters versión 2.4.6 y anteriores, con puntuación CVSS de 9.3. Esta falla permite a atacantes remotos ejecutar comandos SQL arbitrarios contra bases de datos de sitios WordPress afectados, comprometiendo la confidencialidad e integridad de datos. Empresas en LATAM que utilizan este plugin en sitios de comercio electrónico, portales administrativos o plataformas de contenido están expuestas a robo de información sensible y manipulación de registros.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-32566] Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.6…
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-77016] The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user'…
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18080] The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerabl…
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthentic…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18431] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and inclu…
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-19632] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Total Donations para WordPress (CVE-2026-78570)
El plugin Total Donations para WordPress (versiones hasta 2.0.5) contiene una vulnerabilidad de escalada de privilegios con puntuación CVSS 9.8 que permite a atacantes no autenticados obtener permisos de administrador. Esto afecta directamente a sitios de ONG, iglesias y organizaciones benéficas en LATAM que dependen de este plugin para recaudación de fondos. La explotación no requiere autenticación previa, aumentando significativamente el riesgo de compromisos totales del sitio.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78568] The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i…
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive informa…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78477] The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ…
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32563] Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver…
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Crítico vulnerabilidad
24/08/2026
Vulnerabilidad crítica de inclusión de archivos en WP Cafe Pro < 3.0.15
Se ha identificado una vulnerabilidad de inclusión local de archivos (LFI) sin autenticación en WP Cafe Pro versiones anteriores a 3.0.15, con puntuación CVSS 9.8. Esta falla permite a atacantes remotos acceder a archivos sensibles del servidor, incluyendo configuraciones con credenciales de bases de datos. Afecta principalmente a tiendas en línea y sitios de comercio electrónico que utilizan este plugin en WordPress.