Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
984 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.32% | — | Happy AddonsAI | 11/3/2026 | 17/6/2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without… | |
| Aplazada | Alta (8.8) | 0.47% | — | Royal AddonsAI | 11/3/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated… | |
| Aplazada | Alta (8.2) | 0.43% | — | Royal Elementor AddonsAI | 5/3/2026 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1052. | |
| Aplazada | Media (6.5) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1. | |
| Aplazada | Alta (8.8) | 1.1% | — | Master-addons Master Addons FOR ElementorAI | 2/3/2026 | 17/6/2026 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.4) | 0.22% | — | Xpro AddonsAI | 27/2/2026 | 17/6/2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Scroller widget box link attribute in all versions up to, and including, 1.4.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.4) | 0.19% | — | Livemesh Addons FOR Beaver BuilderAI | 26/2/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, the plugin uses… | |
| Aplazada | Media (5.3) | 0.15% | — | Posimyth THE Plus Addons FOR ElementorAI | 22/2/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Shahjada Download Manager Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through <= 1.3.0. | |
| Aplazada | Crítica (9.9) | 0.45% | — | Bravis-themes Bravis AddonsAI | 20/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue affects Bravis Addons: from n/a through <= 1.3.0. | |
| Aplazada | Alta (8.8) | 0.36% | — | Modeltheme Addons FOR Wpbakery AND ElementorAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6. | |
| Aplazada | Alta (8.1) | 0.60% | — | Nenad Obradovic Extensive VC AddonsAIWpbakeryAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-addon allows PHP Local File Inclusion.This issue affects Extensive VC Addons for WPBakery page builder: from n/a through <=… | |
| Aplazada | Media (5.9) | 0.22% | — | Jeweltheme Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4. | |
| Aplazada | Media (6.4) | 0.16% | — | Master-addons Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_table_btn_text' parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.3) | 0.19% | — | Blazethemes News KIT Elementor AddonsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Media (5.3) | 0.24% | — | Wpdeveloper Essential Addons FOR Elementor LiteAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5. | |
| Aplazada | Media (4.3) | 0.18% | — | THE Plus AddonsAI | 18/2/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with… | |
| Aplazada | Alta (7.2) | 0.63% | — | Wpdesk Product Addons FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() function, which passes… | |
| Aplazada | Media (6.5) | 0.33% | — | Elementpack Element Pack AddonsAI | 15/2/2026 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.25% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/2/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpzoom Addons FOR ElementorAI | 11/2/2026 | 17/6/2026 | The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_post_grid_load_more' function in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to retrieve… | |
| Aplazada | Media (5.4) | 0.22% | — | Elementinvader Addons FOR ElementorAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1. | |
| Aplazada | Media (4.3) | 0.12% | — | Themelooks Enter AddonsAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themelooks Enter Addons enteraddons allows Cross Site Request Forgery.This issue affects Enter Addons: from n/a through <= 2.3.2. | |
| Aplazada | Media (5.3) | 0.25% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.5.34. | |
| Aplazada | Media (6.4) | 0.35% | — | Happy AddonsAI | 3/2/2026 | 17/6/2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… |