Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "WordPress" — 1183 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
[CVE-2026-14943] The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress p…
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed i…
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de takeover de cuentas en plugin TrueBooker para WordPress (CVE-2026-14364)
El plugin TrueBooker para WordPress (versiones hasta 1.2.3) permite a atacantes no autenticados resetear contraseñas de usuarios arbitrarios mediante validación insuficiente de identidad. Afecta directamente a sitios de servicios (salones, clínicas, agencias) en LATAM que usan este plugin para reservas. Un atacante podría acceder a cuentas administrativas y comprometer datos de clientes.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin TrueBooker para WordPress
El plugin TrueBooker – Appointment Booking and Scheduler System para WordPress contiene una falla de autorización que permite a atacantes no autenticados cambiar contraseñas de cuentas administrativas en versiones hasta la 1.2.3. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan WordPress para gestión de citas y reservas, exponiendo el control total de sus sitios web.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16619] The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-facto…
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16620] The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-si…
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfi…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-14812] The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a h…
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-12584] The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the …
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13399] The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper autho…
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10524] The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the a…
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10599] The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verif…
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-3430] The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo…
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66705] Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-66447] Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-65553] Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 …
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS Almacenado alta en FormGent para WordPress (CVE-2025-15028)
El plugin FormGent para WordPress es vulnerable a inyección de scripts almacenados (XSS) en campos de formularios hasta la versión 1.9.2 debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta en navegadores de visitantes, comprometiendo datos de formularios y credenciales de clientes. Afecta directamente a pymes y emprendimientos en LATAM que utilizan este plugin para captura de leads, pagos y encuestas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS almacenado alta en plugin TranslatePress para WordPress (CVE-2026-18510)
El plugin TranslatePress de WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en versiones hasta 3.2.6 que permite a atacantes sin autenticación inyectar código malicioso a través de comentarios con marcadores gettext codificados. La falta de sanitización de entrada y escapado de salida afecta directamente a sitios web multilingües en México y LATAM que dependen de este plugin para traducción de contenidos, comprometiendo la integridad y seguridad de visitantes y datos.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16268] The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r…
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16734] The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call…
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18050] The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST r…
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, s…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-16054] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not preven…
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.