Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
983 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.20% | — | Hashthemes Easy Elementor AddonsAI | 20/8/2026 | 24/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | |
| Aplazada | Media (6.6) | 0.38% | — | Royal AddonsAI | 20/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Kalles AddonsAI | 19/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | Animation Addons FOR ElementorAI | 19/8/2026 | 26/8/2026 | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back. | |
| Aplazada | Crítica (9.6) | 0.43% | — | Piotnet Addons FOR Elementor PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | |
| Aplazada | Alta (8.8) | 0.63% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/8/2026 | 20/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render… | |
| Aplazada | Alta (8.1) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/8/2026 | 26/8/2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a… | |
| Aplazada | Media (5.4) | 0.23% | — | Royal AddonsAI | 12/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.26% | — | Ultraaddons Ultra Addons FOR Contact Form 7AI | 7/8/2026 | 12/8/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Element Pack Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Ultimate Store KIT Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (5.3) | 0.35% | — | Element Pack AddonsAI | 6/8/2026 | 12/8/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email… | |
| Aplazada | Media (4.3) | 0.35% | — | Xpro AddonsAI | 5/8/2026 | 12/8/2026 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary… | |
| Aplazada | Media (6.4) | 0.33% | — | Exclusive Addons FOR ElementorAI | 2/8/2026 | 12/8/2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.25% | — | Kingaddons King AddonsAI | 2/8/2026 | 26/8/2026 | The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page. | |
| Aplazada | Media (6.8) | 0.43% | — | Elementpack Element Pack AddonsAI | 2/8/2026 | 26/8/2026 | The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes… | |
| Aplazada | Media (6.1) | 0.25% | — | Ultimate Addons FOR WpbakeryAI | 31/7/2026 | 26/8/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), | |
| Aplazada | Baja (3.5) | 0.24% | — | Wpmet Elementskit Elementor AddonsAI | 31/7/2026 | 26/8/2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious… | |
| Aplazada | Alta (7.2) | 0.66% | — | Wpmet Elementskit Elementor AddonsAI | 31/7/2026 | 26/8/2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing… | |
| Aplazada | Media (6.5) | 0.37% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 30/7/2026 | 30/7/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | |
| Aplazada | Media (5.3) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are… | |
| Aplazada | Media (4.8) | 0.24% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,… | |
| Aplazada | Media (6.1) | 0.25% | — | Animation Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. |