Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
981 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.4) | 0.19% | — | Ultrasaddons Ultra Addons LiteAI | 3/10/2026 | 3/10/2026 | The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.13% | — | Themerex TRX AddonsAI | 2/10/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0. | |
| Aplazada | Media (6.4) | 0.14% | — | Themerex TRX AddonsAI | 2/10/2026 | 2/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0. | |
| Aplazada | Media (6.5) | 0.13% | — | Wpdeveloper Essential Addons FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | |
| Aplazada | Media (6.5) | 0.13% | — | Kingaddons King AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Themerex AddonsAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Themerex AddonsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Kingaddons King AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | THE Plus AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Happy AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Qodeinteractive QI Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Leap13 Premium Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Htmega HT Mega Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Ultra Addons FOR Contact Form 7AI | 26/9/2026 | 28/9/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Aplazada | Media (6.5) | 0.16% | — | Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Wpmet Elementskit Elementor AddonsAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Leap13 Premium Addons FOR ElementorAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Happyaddons FOR ElementorAI | 23/9/2026 | 23/9/2026 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the… | |
| Aplazada | Media (5.3) | 0.23% | — | Ibtana Ecommerce Product AddonsAI | 19/9/2026 | 21/9/2026 | The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.28% | — | WOW Elements Addons FOR ElementorAI | 19/9/2026 | 21/9/2026 | The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or… | |
| Aplazada | Media (6.5) | 0.45% | — | Ultra AddonsAI | 19/9/2026 | 21/9/2026 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler… | |
| Aplazada | Alta (8.1) | 0.58% | — | Master-addons Master Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an… | |
| Aplazada | Media (6.1) | 0.37% | — | Qodeinteractive QI Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Baja (3.8) | 0.26% | — | Kingaddons King AddonsAI | 18/9/2026 | 18/9/2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with… |