Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1954 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Wpthemespace Magical Addons FOR ElementorAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.22% | — | ElementorAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through <= 3.35.5. | |
| Aplazada | Media (6.4) | 0.32% | — | Happy Addons FOR ElementorAI | 11/3/2026 | 17/6/2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of… | |
| Aplazada | Alta (7.2) | 0.43% | — | Unlimited-elements Unlimited ElementsAI | 10/3/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This… | |
| Aplazada | Alta (8.2) | 0.43% | — | Royal Elementor AddonsAI | 5/3/2026 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1052. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Designthemes LMS Elementor PROAI | 5/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4. | |
| Aplazada | Alta (8.8) | 1.1% | — | Master-addons Master Addons FOR ElementorAI | 2/3/2026 | 17/6/2026 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.39% | — | Wpvibes Elementor Addon ElementsAI | 26/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4. | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 Exploit | Elementskit LiteAI | 23/2/2026 | 17/6/2026 | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and… | |
| Aplazada | Media (5.3) | 0.15% | — | Posimyth THE Plus Addons FOR ElementorAI | 22/2/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Shahjada Download Manager Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Add-ons.org PDF FOR Elementor FormsAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.3.1. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themesflat ElementorAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Alta (8.8) | 0.36% | — | Modeltheme Addons FOR Wpbakery AND ElementorAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6. | |
| Aplazada | Alta (8.8) | 0.37% | — | Kamleshyadav Miraculous ElementorAI | 20/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous Elementor: from n/a through <= 2.0.7. | |
| Aplazada | Media (5.9) | 0.22% | — | Jeweltheme Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4. | |
| Aplazada | Media (6.5) | 0.21% | — | ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows Stored XSS.This issue affects Elementor Website Builder: from n/a through <= 3.29.0. | |
| Aplazada | Media (6.4) | 0.16% | — | Master-addons Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_table_btn_text' parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.3) | 0.19% | — | Blazethemes News KIT Elementor AddonsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.33% | — | Elementor Image OptimizerAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Elementor AllyAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2. | |
| Aplazada | Media (5.3) | 0.28% | — | Coolplugins Elementor Contact Form DBAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through <= 2.1.3. | |
| Aplazada | Media (4.3) | 0.11% | — | Wpzita Zita Elementor Site LibraryAI | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Site Request Forgery.This issue affects Zita Elementor Site Library: from n/a through <= 1.6.6. | |
| Aplazada | Media (5.3) | 0.24% | — | Wpdeveloper Essential Addons FOR Elementor LiteAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5. | |
| Aplazada | Media (5.4) | 0.22% | — | Webangon News ElementAI | 19/2/2026 | 17/6/2026 | The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.8. This is due to a missing capability check and nonce verification on the 'ne_clean_data' AJAX action. This makes it possible for authenticated attackers, with… |