Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

984 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.43%—Xpro AddonsAI24/6/202625/6/2026
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.3)0.80%—Brainstormforce Ultimate Addons FOR Beaver BuilderAI20/6/202629/9/2026
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a…
AplazadaMedia (6.5)0.39%—Royal AddonsAI19/6/202622/6/2026
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable()…
AplazadaMedia (6.4)0.34%—Addonspress Advanced ImportAI19/6/202622/6/2026
The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the…
AplazadaAlta (7.1)0.25%—Royal-elementor-addons Royal Elementor Addons PROAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
AplazadaAlta (7.1)0.25%—Wpzoom Addons FOR ElementorAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
AplazadaCrítica (9.9)0.45%—PT Luxa AddonsAI17/6/20266/10/2026
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
AplazadaCrítica (9.8)0.53%—Themerex AddonsAI17/6/20266/10/2026
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
AplazadaMedia (6.5)0.22%—Kingaddons King Addons FOR ElementorAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.
AplazadaMedia (6.4)0.29%—Ultra AddonsAI15/6/202617/6/2026
Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.
AplazadaMedia (5.3)0.29%—Wpdeveloper Essential Addons FOR ElementorAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
AplazadaMedia (6.4)0.36%—Athemes Addons FOR ElementorAI10/6/202623/7/2026
The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.4)0.15%—Animation Addons FOR ElementorAI10/6/202623/7/2026
The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.4)0.43%—Prime Elementor AddonsAI9/6/202623/7/2026
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.56%💥 PoCWpdeveloper Essential Addons FOR ElementorAI6/6/202623/7/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated…
AplazadaMedia (6.4)0.38%—Master-addons Master Addons FOR ElementorAI6/6/202623/7/2026
The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output…
AplazadaMedia (6.4)0.33%—Theplus Plus Addons FOR ElementorAI29/5/202621/7/2026
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is…
AplazadaMedia (5.3)0.31%—Wpmet Elementskit Elementor Addons LiteAI27/5/202617/6/2026
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
AplazadaMedia (4.3)0.25%—Wpmet Elementskit Elementor Addons LiteAI27/5/202617/6/2026
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
AplazadaMedia (6.5)0.28%—Xpro Elementor Addons PROAI27/5/20267/10/2026
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can…
AplazadaMedia (6.4)0.30%—Livemesh Addons FOR Beaver BuilderAI27/5/202617/6/2026
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user…
AplazadaMedia (6.4)0.30%—Livemesh Wpbakery Page Builder AddonsAI27/5/202617/6/2026
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check…
AplazadaMedia (6.4)0.24%—Livemesh Wpbakery Page Builder AddonsAI27/5/202617/6/2026
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. Specifically, shortcode…
AplazadaMedia (5.3)0.25%—Xpro AddonsAI20/5/202624/7/2026
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates.
AplazadaCrítica (9.8)0.87%💥 PoCPiotnet Addons FOR Elementor PROAI19/5/202624/7/2026
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe…