Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Header Footer Builder FOR ElementorAI | 16/7/2026 | 16/7/2026 | The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to display site-wide, injecting JavaScript… | |
| Aplazada | Media (6.4) | 0.44% | — | News KIT Addons FOR ElementorAI | 14/7/2026 | 14/7/2026 | The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock Jetblocks FOR ElementorAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0. | |
| Aplazada | Alta (7.5) | 0.51% | — | Codexthemes Thegem Theme ElementsAI | 13/7/2026 | 14/8/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Elementinvader Addons FOR ElementorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3. | |
| Aplazada | Media (5) | 0.22% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/7/2026 | 13/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry.… | |
| Aplazada | Alta (8.8) | 0.67% | — | Wpdeveloper Essential Addons FOR ElementorAI | 11/7/2026 | 15/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct… | |
| Aplazada | Media (4.9) | 0.29% | — | Leap13 Premium Addons FOR ElementorAI | 11/7/2026 | 14/7/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.96% | — | La-studio Element KITAI | 11/7/2026 | 14/7/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on… | |
| Aplazada | Media (6.4) | 0.36% | — | JEG KIT FOR ElementorAI | 10/7/2026 | 10/7/2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6. This is due to insufficient input sanitization and output… | |
| Aplazada | Media (5.3) | 0.30% | — | La-studio Element KITAI | 10/7/2026 | 10/7/2026 | The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled… | |
| Aplazada | Media (6.4) | 0.33% | — | Animation Addons FOR ElementorAI | 10/7/2026 | 10/7/2026 | The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' parameters of the Weather widget in all versions up to, and including, 2.6.3. This is due to insufficient output escaping in the Weather widget's render() function at… | |
| Aplazada | Media (6.4) | 0.36% | — | Posimyth THE Plus Addons FOR ElementorAI | 10/7/2026 | 10/7/2026 | The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passed the raw `custom_attributes` string… | |
| Aplazada | Media (6.4) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 8/7/2026 | 8/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events… | |
| Aplazada | Media (6.4) | 0.32% | — | Sympl Repeater FOR ACF AND ElementorAI | 8/7/2026 | 8/7/2026 | The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to… | |
| Aplazada | Media (6.4) | 0.32% | — | Exclusive Addons FOR ElementorAI | 7/7/2026 | 7/7/2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (5.3) | 0.33% | — | TIM Strifler Exclusive Addons ElementorAI | 5/7/2026 | 6/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9. | |
| Aplazada | Media (4.3) | 0.39% | — | Envothemes Templates Widgets FOR Elementor AND WoocommerceAI | 2/7/2026 | 2/7/2026 | The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a… | |
| Aplazada | Media (6.4) | 0.26% | — | Crocoblock Jetwidgets FOR ElementorAI | 1/7/2026 | 1/7/2026 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Easy Elements FOR ElementorAI | 26/6/2026 | 29/6/2026 | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | Live Copy Paste FOR ElementorAI | 26/6/2026 | 5/10/2026 | Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | TIM Strifler Exclusive Addons ElementorAI | 26/6/2026 | 26/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | |
| Aplazada | Media (6.5) | 0.37% | — | ElementorAI | 25/6/2026 | 25/6/2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… |