Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 617 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
22/06/2026
[CVE-2026-6858] The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displaye…
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
M Alto vulnerabilidad
20/06/2026
[CVE-2020-37255] WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows un…
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.
M Crítico vulnerabilidad
20/06/2026
[CVE-2019-25763] WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability…
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and a…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-11912] The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insuff…
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the administrator has not enabled the AllowFrontManage setting, because the is_admin() ch…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-11911] The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie…
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). T…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-9843] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbi…
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is dele…
M Crítico vulnerabilidad
20/06/2026
[CVE-2026-11551] The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve…
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their ac…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-7515] The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and…
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code e…
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-8713] The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insu…
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-confi…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-11395] The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions…
The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_trigger. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Exploitation requires that the admin-co…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-9860] The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code …
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-12407] The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorizatio…
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's index_action() nonce gate is bypassed entirely — while reading an attacker-controll…
M Alto vulnerabilidad
17/06/2026
[CVE-2025-69130] Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.…
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme
M Alto vulnerabilidad
17/06/2026
[CVE-2025-69115] Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2…
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme
M Alto vulnerabilidad
17/06/2026
[CVE-2026-9570] The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before ech…
The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/06/2026
[CVE-2026-8089] The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommer…
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrator…
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-25470] Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom …
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
M Alto vulnerabilidad
17/06/2026
[CVE-2026-22343] Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.
Unauthenticated Broken Access Control in WordPress Dating Theme
M Alto vulnerabilidad
17/06/2026
[CVE-2026-22342] Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme
M Alto vulnerabilidad
17/06/2026
[CVE-2026-12360] The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and includin…
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL constructi…