Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 617 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad
17/07/2026
[CVE-2026-13352] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C…
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the …
M Alto vulnerabilidad
17/07/2026
[CVE-2026-15395] The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored C…
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an …
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-14956] The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an…
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator acco…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-7543] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' pa…
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15005] The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses …
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15008] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for …
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15103] The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress…
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_op…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13741] The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege…
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administr…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12585] The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity…
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12978] The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before ref…
The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-12492] The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-ti…
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12525] The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri…
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) fe…
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-15013] The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via …
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally co…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13042] The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con…
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time kses sanitizat…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12753] The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable t…
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/07/2026
[CVE-2026-12997] The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a…
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly acce…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-12512] The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied…
The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-12281] The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode…
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automat…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-13001] The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to mi…
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12511] The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using…
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.