Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

983 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.6)0.20%—Hashthemes Easy Elementor AddonsAI20/8/202624/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
AplazadaMedia (6.6)0.38%—Royal AddonsAI20/8/202626/8/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution…
AplazadaCrítica (9.8)0.56%—Kalles AddonsAI19/8/202620/8/2026
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
AplazadaAlta (7.2)0.27%—Animation Addons FOR ElementorAI19/8/202626/8/2026
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
AplazadaCrítica (9.6)0.43%—Piotnet Addons FOR Elementor PROAI18/8/202620/8/2026
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
AplazadaAlta (8.8)0.63%—Royal-elementor-addons Royal Elementor AddonsAI16/8/202620/8/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render…
AplazadaAlta (8.1)0.38%—Wpdeveloper Essential Addons FOR ElementorAI14/8/202626/8/2026
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a…
AplazadaMedia (5.4)0.23%—Royal AddonsAI12/8/202626/8/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (6.4)0.26%—Ultraaddons Ultra Addons FOR Contact Form 7AI7/8/202612/8/2026
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.5)0.22%—Brainstormforce Ultimate Addons FOR ElementorAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
AplazadaMedia (5.3)0.33%—Element Pack Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
AplazadaMedia (6.5)0.27%—Ultimate Store KIT Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (5.3)0.35%—Element Pack AddonsAI6/8/202612/8/2026
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email…
AplazadaMedia (4.3)0.35%—Xpro AddonsAI5/8/202612/8/2026
The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary…
AplazadaMedia (6.4)0.33%—Exclusive Addons FOR ElementorAI2/8/202612/8/2026
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.1)0.25%—Kingaddons King AddonsAI2/8/202626/8/2026
The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.
AplazadaMedia (6.8)0.43%—Elementpack Element Pack AddonsAI2/8/202626/8/2026
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes…
AplazadaMedia (6.1)0.25%—Ultimate Addons FOR WpbakeryAI31/7/202626/8/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),
AplazadaBaja (3.5)0.24%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious…
AplazadaAlta (7.2)0.66%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing…
AplazadaMedia (6.5)0.37%—Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI30/7/202630/7/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.
AplazadaMedia (5.3)0.32%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are…
AplazadaMedia (4.8)0.24%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,…
AplazadaMedia (6.1)0.25%—Animation Addons FOR ElementorAI30/7/202630/7/2026
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.
AplazadaAlta (7.1)0.25%—Themefic Ultimate Addons FOR Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.