Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
1951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Wpmet Elementskit Elementor AddonsAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Leap13 Premium Addons FOR ElementorAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Happyaddons FOR ElementorAI | 23/9/2026 | 23/9/2026 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the… | |
| Aplazada | Alta (7.5) | 0.40% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/9/2026 | 21/9/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the… | |
| Aplazada | Media (6.5) | 0.28% | — | WOW Elements Addons FOR ElementorAI | 19/9/2026 | 21/9/2026 | The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or… | |
| Aplazada | Alta (8.1) | 0.58% | — | Master-addons Master Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an… | |
| Aplazada | Media (6.1) | 0.37% | — | Qodeinteractive QI Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.4) | 0.23% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Kingaddons King Addons FOR ElementorAI | 17/9/2026 | 17/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Sktthemes SKT Addons FOR ElementorAI | 17/9/2026 | 19/9/2026 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Element Pack Elementor AddonsAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Htmega HT Mega Addons FOR ElementorAI | 17/9/2026 | 18/9/2026 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the… | |
| Aplazada | Media (5.4) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/9/2026 | 16/9/2026 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on… | |
| Aplazada | Alta (7.6) | 0.38% | — | Wowdevs SKY Addons FOR ElementorAI | 11/9/2026 | 11/9/2026 | Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Jeweltheme Master Addons FOR ElementorAI | 11/9/2026 | 11/9/2026 | Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | |
| Aplazada | Media (5.3) | 0.16% | — | Persian ElementorAI | 11/9/2026 | 11/9/2026 | The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different… | |
| Aplazada | Media (6.1) | 0.45% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.5) | 0.33% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString()… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Drag AND Drop File Upload FOR Elementor FormsAI | 10/9/2026 | 10/9/2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | |
| Aplazada | Media (6.1) | 0.38% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/9/2026 | 8/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.31% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/9/2026 | 3/9/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpkoi Templates FOR ElementorAI | 3/9/2026 | 7/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. |