Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
984 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.32% | — | Royal-elementor-addons Royal Elementor AddonsAI | 14/5/2026 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.31% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Posimyth THE Plus Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including, 6.4.11 due to insufficient input… | |
| Aplazada | Media (4.3) | 0.35% | — | Rtmkit Addons FOR ElementorAI | 13/5/2026 | 17/6/2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Alta (8.8) | 0.82% | — | Rtmkit AddonsAI | 13/5/2026 | 17/6/2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP… | |
| Aplazada | Alta (8.5) | 0.36% | — | Xpro Elementor AddonsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.4) | 0.35% | — | SKY AddonsAI | 8/5/2026 | 17/6/2026 | The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, 3.3.2. This is due to the custom post type being registered with `capability_type => 'post'` and `show_in_rest => true`, combined with insufficient input… | |
| Aplazada | Media (6.5) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (5.3) | 0.33% | — | Wedevs Happy Addons FOR ElementorAI | 7/5/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8. | |
| Aplazada | Media (5.3) | 0.31% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (6.4) | 0.36% | — | Royal AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.2) | 0.42% | — | Royal-elementor-addons Royal Elementor AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked… | |
| Aplazada | Media (5.4) | 0.24% | — | Leap13 Premium Addons FOR ElementorAI | 2/5/2026 | 17/6/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.46% | — | Royal AddonsAI | 2/5/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it… | |
| Aplazada | Alta (7.2) | 0.48% | — | Royal-elementor-addons Royal Elementor AddonsAI | 2/5/2026 | 18/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query… | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce SpectraAIBrainstormforce Ultimate-addons-for-gutenbergAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22. | |
| Analizada | Alta (7.8) | 0.25% | — | KDE Kcoreaddons | 28/4/2026 | 17/6/2026 | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input… | |
| Aplazada | Media (6.4) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 24/4/2026 | 14/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of… | |
| Aplazada | Media (5.3) | 0.73% | 💥 Exploit | Htmega HT Mega AddonsAI | 23/4/2026 | 17/6/2026 | The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days | |
| Aplazada | Media (6.4) | 0.33% | — | Royal AddonsAI | 17/4/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.8) | 0.82% | — | Livemesh Addons FOR ElementorAI | 16/4/2026 | 17/6/2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name parameter in the `lae_get_template_part()` function, which uses an inadequate `str_replace()` approach that can be… | |
| Aplazada | Media (6.4) | 0.32% | — | Livemesh Addons FOR ElementorAI | 16/4/2026 | 17/6/2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0. This is due to missing authorization checks on the AJAX handler `lae_admin_ajax()` and insufficient output escaping on… | |
| Aplazada | Media (5.3) | 0.29% | — | Royal Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056. | |
| Aplazada | Alta (7.6) | 0.38% | — | Bdthemes Element Pack Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2. | |
| Aplazada | Alta (8.8) | 0.82% | — | Vertex AddonsAI | 9/4/2026 | 24/7/2026 | The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check does not terminate… |