Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81429] The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF c…
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81742] The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before…
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77005] The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file pa…
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77006] The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, doe…
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77705] The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify tha…
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-75800] The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML…
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XCS en plugin Kirki para WordPress afecta hasta versión 6.2.0
El plugin Kirki (Freeform Page Builder) para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en el parámetro 'comment' que permite a atacantes no autenticados inyectar scripts maliciosos. La falta de sanitización de entrada y escapado de salida afecta todas las versiones hasta 6.2.0, comprometiendo sitios web de empresas, agencias digitales y plataformas de comercio electrónico en LATAM que utilizan este constructor de páginas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-85677] The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordP…
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visito…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14563] The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before i…
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-74925] The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capab…
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14559] The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password befo…
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14560] The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded fi…
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-8778] The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for …
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-81754] The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPres…
The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-81825] The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cros…
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including,

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-19991] The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and inc…
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-18579] The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'H…
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The n…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-15462] The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields'…
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-18561] The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'ad…
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbati…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-77807] The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi…
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires…