Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

983 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.37%—Qodeinteractive QI Addons FOR ElementorAI18/9/202619/9/2026
The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaBaja (3.8)0.26%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with…
AplazadaBaja (2.7)0.32%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they…
AplazadaMedia (6.8)0.43%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by…
AplazadaMedia (5.3)0.29%—Kingaddons King Addons FOR ElementorAI17/9/202617/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
AplazadaAlta (7.6)0.38%—Sktthemes SKT Addons FOR ElementorAI17/9/202619/9/2026
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
AplazadaMedia (6.5)0.22%—Element Pack Elementor AddonsAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
AplazadaMedia (5.3)0.30%—Master-addons Master AddonsAI17/9/202618/9/2026
The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
AplazadaMedia (6.8)0.43%—Htmega HT Mega Addons FOR ElementorAI17/9/202618/9/2026
The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the…
AplazadaMedia (5.4)0.22%—Royal-elementor-addons Royal Elementor AddonsAI16/9/202616/9/2026
The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on…
AplazadaMedia (6.8)0.43%—Xpro AddonsAI16/9/202617/9/2026
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigation call, allowing users with the contributor role and above to inject and store JavaScript that executes in the browser of anyone who…
AplazadaMedia (5.3)0.32%—Royal AddonsAI12/9/202614/9/2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all…
AplazadaAlta (7.6)0.38%—Wowdevs SKY Addons FOR ElementorAI11/9/202611/9/2026
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
AplazadaCrítica (9.8)0.56%—Themerex AddonsAI11/9/202611/9/2026
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
AplazadaAlta (7.1)0.32%—Jeweltheme Master Addons FOR ElementorAI11/9/202611/9/2026
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
AplazadaMedia (6.8)0.43%—Kingaddons King AddonsAI5/9/20268/9/2026
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in…
AplazadaMedia (5.3)0.33%—Xpro AddonsAI4/9/20268/9/2026
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of…
AplazadaMedia (6.8)0.43%—Xpro AddonsAI2/9/20263/9/2026
The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaAlta (7.2)1.2%—Master-addons Master AddonsAI1/9/20261/9/2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the…
AplazadaMedia (6.5)0.22%—Kalles AddonsAI31/8/20261/9/2026
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
AplazadaMedia (5.3)0.40%—Wpdeveloper Essential Addons FOR ElementorAI28/8/202628/8/2026
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.8)0.23%—Royal AddonsAI26/8/202626/8/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (5.3)0.24%—Royal AddonsAI26/8/202626/8/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.
AplazadaMedia (5.3)0.22%—Royal AddonsAI26/8/202626/8/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post,…