Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
984 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.43% | — | Xpro AddonsAI | 24/6/2026 | 25/6/2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.3) | 0.80% | — | Brainstormforce Ultimate Addons FOR Beaver BuilderAI | 20/6/2026 | 29/9/2026 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a… | |
| Aplazada | Media (6.5) | 0.39% | — | Royal AddonsAI | 19/6/2026 | 22/6/2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable()… | |
| Aplazada | Media (6.4) | 0.34% | — | Addonspress Advanced ImportAI | 19/6/2026 | 22/6/2026 | The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom Addons FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions. | |
| Aplazada | Crítica (9.9) | 0.45% | — | PT Luxa AddonsAI | 17/6/2026 | 6/10/2026 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Themerex AddonsAI | 17/6/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Kingaddons King Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions. | |
| Aplazada | Media (6.4) | 0.29% | — | Ultra AddonsAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | |
| Aplazada | Media (6.4) | 0.36% | — | Athemes Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.15% | — | Animation Addons FOR ElementorAI | 10/6/2026 | 23/7/2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.43% | — | Prime Elementor AddonsAI | 9/6/2026 | 23/7/2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.56% | 💥 PoC | Wpdeveloper Essential Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.38% | — | Master-addons Master Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output… | |
| Aplazada | Media (6.4) | 0.33% | — | Theplus Plus Addons FOR ElementorAI | 29/5/2026 | 21/7/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is… | |
| Aplazada | Media (5.3) | 0.31% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (6.5) | 0.28% | — | Xpro Elementor Addons PROAI | 27/5/2026 | 7/10/2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Addons FOR Beaver BuilderAI | 27/5/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check… | |
| Aplazada | Media (6.4) | 0.24% | — | Livemesh Wpbakery Page Builder AddonsAI | 27/5/2026 | 17/6/2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. Specifically, shortcode… | |
| Aplazada | Media (5.3) | 0.25% | — | Xpro AddonsAI | 20/5/2026 | 24/7/2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates. | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Piotnet Addons FOR Elementor PROAI | 19/5/2026 | 24/7/2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe… |