Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1956 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.28% | — | Merkulove Comparimager FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Uper FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Uper for Elementor uper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uper for Elementor: from n/a through <= 1.0.5. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Audier FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audier For Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Motionger FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Motionger for Elementor motionger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motionger for Elementor: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Searcher FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Searcher for Elementor searcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Searcher for Elementor: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.4) | 0.28% | — | Merkulove Carter FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Carter for Elementor carter-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carter for Elementor: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Imager FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Imager for Elementor imager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Imager for Elementor: from n/a through <= 2.0.4. | |
| Aplazada | Media (6.5) | 0.27% | — | Themegoods Grand Restaurant Theme Elements FOR ElementorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Bdthemes Element Pack Elementor AddonsAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Cross Site Request Forgery.This issue affects Element Pack Elementor Addons: from n/a through <= 8.3.13. | |
| Aplazada | Crítica (9.8) | 1.1% | 💥 PoC | La-studio Element KITAI | 22/1/2026 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 16/1/2026 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft,… | |
| Aplazada | Media (6.5) | 0.21% | — | Pencilwp X Addons FOR ElementorAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows DOM-Based XSS.This issue affects X Addons for Elementor: from n/a through <= 1.0.23. | |
| Aplazada | Media (6.4) | 0.23% | — | Jegtheme JEG Elementor KITAI | 8/1/2026 | 17/6/2026 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.1 due to insufficient input sanitization in the countdown widget's redirect functionality. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.21% | — | Theplus Innovation THE Plus Addons FOR Elementor PROAI | 7/1/2026 | 7/10/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7. | |
| Aplazada | Media (6.5) | 0.24% | — | Cyberchimps Responsive Addons FOR ElementorAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Addons for Elementor: from n/a through <= 2.0.8. | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme ElementsAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements allows DOM-Based XSS.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.11.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme Elements FOR ElementorAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows Stored XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Codexthemes Thegem Theme Elements ElementorAI | 6/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0. | |
| Aplazada | Media (6.5) | 0.15% | — | Posimyth THE Plus Addons FOR Elementor Page Builder LiteAI | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.3.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpvibes Anywhere Elementor PROAI | 5/1/2026 | 7/10/2026 | Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29. | |
| Aplazada | Media (4.3) | 0.30% | — | Premio MY Sticky ElementsAI | 1/1/2026 | 17/6/2026 | The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible… | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Conformer FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conformer for Elementor: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Logger FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logger for Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Worker FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for Elementor: from n/a through <= 1.0.10. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Headinger FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headinger for Elementor: from n/a through <= 1.1.4. |