Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Multiple Vendors" — 5304 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-104801] The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbi…
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is …
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-107742] The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is…
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-100196] The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to St…
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-100161] The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site …
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an inje…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-96667] The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable t…
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-96682] The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont…
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Tag in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-92975] The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr…
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.3 via the `create_support_user()` function. This is due to the function identifying the support account solely by matching against publicly hardcoded constants — `user_login` `'groundhogg'` and email addresses `'support@groundhogg.io'` / `…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-93775] The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is trigger…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-94256] The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the…
The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-94257] The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being chang…
The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing unauthenticated attackers to set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-77183] The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege e…
The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with FooSales Cashier-level access and above, to change arb…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-83526] The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a…
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player cre…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-87780] The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted…
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-87781] The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter befo…
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-14335] The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is …
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104766] The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPres…
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` p…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104899] The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPre…
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. Thi…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104752] The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file up…
The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104723] The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable t…
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via deserialization of untrusted input . This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vuln…
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-104725] The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr…
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress u…