Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1951 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.5)0.24%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious…
AplazadaAlta (7.2)0.66%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing…
AplazadaMedia (5.3)0.32%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are…
AplazadaMedia (4.8)0.24%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,…
AplazadaMedia (6.1)0.25%—Animation Addons FOR ElementorAI30/7/202630/7/2026
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.
AplazadaMedia (5.3)0.33%—Persian ElementorAI30/7/202630/7/2026
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for…
Pendiente de análisisBaja (2)0.37%—Python Xml.etree.elementtreeAI28/7/202613/8/2026
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with…
AplazadaAlta (7.1)0.25%—Database FOR Contact Form 7 Wpforms Elementor FormsAI28/7/202628/7/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (5.3)0.33%—Exclusiveaddons Exclusive Addons ElementorAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
AplazadaMedia (5.9)0.24%—Elementor Image CarouselAI23/7/202623/7/2026
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
AplazadaMedia (5.3)0.33%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.5)0.22%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
AplazadaMedia (5.3)0.31%—La-studioweb Element KIT FOR ElementorAI23/7/202630/9/2026
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
AplazadaAlta (7.1)0.13%—La-studioweb Element KIT FOR ElementorAI23/7/202630/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
AplazadaMedia (6.5)0.22%—La-studioweb Element KIT FOR ElementorAI23/7/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3.
AplazadaMedia (6.4)0.42%—Brainstormforce Ultimate Addons FOR ElementorAI22/7/202622/7/2026
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (4.3)0.35%—Themeum Tutor LMS Elementor AddonsAI21/7/202622/7/2026
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for…
AplazadaMedia (6.4)0.42%—Wpdeveloper Essential Addons FOR ElementorAI21/7/202623/7/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaAlta (8.8)0.51%—Free Builder FOR ElementorAI21/7/202621/7/2026
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form…
AplazadaMedia (6.4)0.35%—Wpdeveloper Essential Addons FOR ElementorAI21/7/202622/7/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (4.9)0.40%—ElementorAI20/7/202620/7/2026
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts…
AplazadaAlta (8.8)0.51%—Unlimited-elements Unlimited Elements FOR ElementorAI20/7/202621/7/2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver…
AplazadaMedia (4.3)0.19%—W3sc Elementor TO Zoho CRMAI18/7/202622/7/2026
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration…
AplazadaMedia (5.3)0.34%—Royaladdons Royal Addons FOR ElementorAI17/7/202617/7/2026
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu…