Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
[CVE-2026-80071] The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may…
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-15451] The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in ver…
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev…
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica de ejecución remota de código en The Events Calendar para WordPress hasta versión 6.17.4
The Events Calendar plugin para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones hasta 6.17.4. La falla reside en la función is_safe_widget_instance que puede ser eludida mediante métodos mágicos de PHP durante el pre-parseo, permitiendo a atacantes no autenticados ejecutar código arbitrario. Empresas en LATAM que operan sitios WordPress con este plugin están expuestas a compromisos críticos de integridad y disponibilidad.
M Crítico vulnerabilidad
12/09/2026
RCE crítica en The Events Calendar para WordPress hasta v6.17.3
The Events Calendar plugin para WordPress es vulnerable a Ejecución Remota de Código (RCE) en todas las versiones hasta 6.17.3. La vulnerabilidad existe en la función parse_array() debido a validación insuficiente del mapa 'classes' del widget, permitiendo que payloads de arrays simples eluda el control is_safe_widget_instance() y alcance el punto de invocación de funciones. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin popular para gestión de eventos.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin Tutor LMS para WordPress
El plugin Tutor LMS (versiones ≤4.0.7) contiene una vulnerabilidad de inyección de objetos PHP en el manejador AJAX `tutor_save_withdraw_account` que permite a atacantes no autenticados ejecutar código mediante el parámetro `withdraw_method_field`. Afecta principalmente a plataformas de educación en línea y cursos corporativos en LATAM que dependen de este plugin en WordPress. El riesgo es alta (CVSS 8.8) al carecer de validación de capacidades/roles, confiando solo en nonce.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inclusión de archivos locales en plugin GEO my WP para WordPress
El plugin GEO my WP en todas las versiones hasta 4.5.5.3 es vulnerable a Local File Inclusion (LFI) a través de la función gmw_posts_locator_ajax_info_window_loader. Atacantes sin autenticación pueden incluir y ejecutar archivos PHP arbitrarios en el servidor, comprometiendo la integridad del sitio y permitiendo ejecución de código malicioso. Esta vulnerabilidad afecta significativamente a sitios inmobiliarios, directorios y plataformas de ubicación operadas en LATAM.
M Alto vulnerabilidad
12/09/2026
Inyección SQL en plugin rtMedia para WordPress afecta versiones hasta 4.7.11
El plugin rtMedia para WordPress, BuddyPress y bbPress es vulnerable a inyección SQL ciega basada en tiempo a través del parámetro 'compare' en todas las versiones hasta la 4.7.11. Atacantes no autenticados pueden ejecutar consultas SQL adicionales explotando insuficiente validación de entrada. Esta vulnerabilidad afecta especialmente a sitios de medios, redes sociales corporativas y comunidades en línea operadas por empresas mexicanas y latinoamericanas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84099] The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a …
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-84171] The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of u…
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-85681] The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one …
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled …
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87759] The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check…
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87842] The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check be…
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87888] The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST rout…
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-82845] The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metad…
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the s…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84047] The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parame…
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77752] The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user req…
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promo…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-80491] The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input befor…
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-80494] The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before …
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81090] The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploa…
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-81402] The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verifica…
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.