Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 32 min
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-91832] The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings …
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92994] The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents …
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-89193] The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTM…
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-88797] The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX act…
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-85573] The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload typ…
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-75873] The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one o…
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-75823] The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned …
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96649] The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress i…
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87741] The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versi…
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed …
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96896] The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perfor…
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-86609] The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted throu…
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-81655] The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its set…
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-82901] The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due …
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-85984] The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-77203] The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalati…
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96524] The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress …
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96532] The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership ch…
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
M Crítico vulnerabilidad
26/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin Request a Quote for WooCommerce
El plugin Request a Quote for WooCommerce para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta la 2.9.2 debido a validación insuficiente de extensiones y tipos MIME en la función afrfq_submit_quote_via_popup(). Un atacante puede cargar archivos maliciosos (como shells PHP) directamente al servidor sin restricción, comprometiendo completamente sitios de comercio electrónico en LATAM. Con CVSS 9.8, afecta principalmente a pequeñas y medianas empresas que usan este plugin para gestionar cotizaciones de productos.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84095] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.