Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
492 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 22/7/2026 | 22/7/2026 | The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 22/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.34% | — | Royaladdons Royal Addons FOR ElementorAI | 17/7/2026 | 17/7/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu… | |
| Aplazada | Media (6.4) | 0.44% | — | News KIT Addons FOR ElementorAI | 14/7/2026 | 14/7/2026 | The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.25% | — | Elementinvader Addons FOR ElementorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3. | |
| Aplazada | Alta (8.8) | 0.67% | — | Wpdeveloper Essential Addons FOR ElementorAI | 11/7/2026 | 15/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct… | |
| Aplazada | Media (4.9) | 0.29% | — | Leap13 Premium Addons FOR ElementorAI | 11/7/2026 | 14/7/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.33% | — | Animation Addons FOR ElementorAI | 10/7/2026 | 10/7/2026 | The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' parameters of the Weather widget in all versions up to, and including, 2.6.3. This is due to insufficient output escaping in the Weather widget's render() function at… | |
| Aplazada | Media (6.4) | 0.36% | — | Posimyth THE Plus Addons FOR ElementorAI | 10/7/2026 | 10/7/2026 | The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passed the raw `custom_attributes` string… | |
| Aplazada | Media (6.4) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 8/7/2026 | 8/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events… | |
| Aplazada | Media (6.4) | 0.32% | — | Exclusive Addons FOR ElementorAI | 7/7/2026 | 7/7/2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom Addons FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Kingaddons King Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | |
| Aplazada | Media (6.4) | 0.36% | — | Athemes Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.15% | — | Animation Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (5.3) | 0.56% | 💥 PoC | Wpdeveloper Essential Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.38% | — | Master-addons Master Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output… | |
| Aplazada | Media (6.4) | 0.33% | — | Theplus Plus Addons FOR ElementorAI | 29/5/2026 | 21/7/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Piotnet Addons FOR Elementor PROAI | 19/5/2026 | 24/7/2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe… | |
| Aplazada | Media (6.5) | 0.31% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Posimyth THE Plus Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including, 6.4.11 due to insufficient input… | |
| Aplazada | Media (4.3) | 0.35% | — | Rtmkit Addons FOR ElementorAI | 13/5/2026 | 17/6/2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (5.3) | 0.33% | — | Wedevs Happy Addons FOR ElementorAI | 7/5/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8. |