Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 39 min
Buscando: "WordPress" — 364 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54239] Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticate…
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86801] The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does n…
The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files alread…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87963] The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username reques…
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-88795] The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authenticat…
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88904] The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST rou…
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-91014] The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise an…
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86707] The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate …
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86709] The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session …
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86710] The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in…
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87786] The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at che…
The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88792] The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in…
The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
M Alto vulnerabilidad
17/09/2026
[CVE-2025-15697] The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in …
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85130] The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a p…
The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-87796] The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in …
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87935] The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to…
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated…
M Alto vulnerabilidad
16/09/2026
Inyección SQL en WP Mega Menu permite acceso no autorizado a bases de datos
Se ha identificado una vulnerabilidad de inyección SQL ciega (CVSS 7.6) en el complemento WP Mega Menu para WordPress, versiones hasta 1.4.2. Empresas que utilizan este plugin en sitios de comercio electrónico, portales corporativos y aplicaciones con datos sensibles en México y LATAM están expuestas a extracción no autorizada de información de bases de datos. Un atacante remoto puede ejecutar comandos SQL maliciosos sin autenticación.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89063] The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to …
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full AI booking conversation transcript of any customer — leaking names…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-78088] The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is…
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files wh…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-18595] The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJ…
The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.