Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 242 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 7 horas
Inyección SQL ciega en Ajax Search Pro afecta sitios WordPress en LATAM
Una vulnerabilidad crítica de inyección SQL (CVSS 9.3) en el plugin Ajax Search Pro para WordPress permite a atacantes ejecutar consultas SQL ciegas sin autenticación. Afecta versiones hasta 4.29.1 y representa riesgo severo para e-commerce, portales y sitios corporativos que usen este plugin en México y Latinoamérica, exponiendo datos de clientes y configuraciones de base de datos.
M Crítico vulnerabilidad Nuevo
Hace 7 horas
Inyección SQL ciega crítica en plugin WPLMS afecta sitios WordPress en LATAM
Se identificó una vulnerabilidad de inyección SQL ciega (CVE-2026-96327, CVSS 9.3) en VibeThemes WPLMS versiones anteriores a 1.9.9.8.2. Un atacante puede manipular comandos SQL a través de parámetros no sanitizados, comprometiendo bases de datos de sitios educativos y empresariales. Dado que WPLMS es popular en plataformas e-learning de México y LATAM, la exposición es significativa.
M Crítico vulnerabilidad Nuevo
Hace 7 horas
Inyección SQL ciega crítica en tagDiv Opt-In Builder versiones ≤1.7.6
Se ha identificado una vulnerabilidad de inyección SQL ciega (CVE-2026-96330, CVSS 9.3) en tagDiv Opt-In Builder que permite a atacantes ejecutar comandos SQL maliciosos sin validación adecuada de entrada. Esta falla afecta principalmente a sitios WordPress en México y Latinoamérica que utilizan este plugin para gestionar suscripciones y recopilación de datos. Un atacante podría extraer información sensible de bases de datos, comprometer credenciales o alterar registros críticos de clientes.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-85097] The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versi…
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a …
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-103692] The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce che…
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-103646] The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logg…
The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, includi…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-17609] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-32579] Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress
M Crítico vulnerabilidad
Hace 5 días
Inyección SQL ciega crítica en Unlimited Elements for Elementor (CVSS 9.3)
Vulnerabilidad de inyección SQL en el plugin Unlimited Elements for Elementor (versiones hasta 2.0.20) permite a atacantes ejecutar consultas maliciosas contra bases de datos de sitios WordPress. Afecta principalmente a agencias digitales y empresas en LATAM que utilizan este plugin de diseño para construir landing pages y portales. El impacto es crítico: acceso no autorizado a datos sensibles, robo de credenciales y compromiso total del sitio.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica en Beaver Builder permite ejecución de código en sitios WordPress
El plugin Beaver Builder Page Builder para WordPress (versiones hasta 2.11.0.5) contiene una vulnerabilidad de ejecución arbitraria de shortcodes que permite a atacantes no autenticados ejecutar código malicioso. Afecta directamente a miles de sitios web de empresas, agencias y e-commerce en México y LATAM que utilizan este constructor visual popular. La falta de validación adecuada en la función do_shortcode expone datos sensibles y control total del sitio.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica en plugin VikAppointments para WordPress permite eliminación arbitraria de archivos
El plugin VikAppointments Services Booking Calendar en WordPress (versiones hasta 1.2.21) contiene una falla de validación de rutas que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Esta capacidad de eliminación puede ser explotada para lograr ejecución remota de código eliminando archivos críticos del sistema, afectando especialmente a empresas de servicios y agendamientos online en LATAM que utilizan este plugin.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19652] The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an…
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-94541] The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization b…
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the p…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-97637] The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Coo…
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-15896] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19660] The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up t…
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled …
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-14378] The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator …
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by …
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-62071] Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Unauthenticated SQL Injection in WordPress File Upload
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-75957] The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable…
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-15989] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalatio…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag…