Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

490 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.13%—Wpdeveloper Essential Addons FOR ElementorAI1/10/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4.
AplazadaMedia (6.5)0.18%—Qodeinteractive QI Addons FOR ElementorAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.
AplazadaMedia (6.5)0.16%—Leap13 Premium Addons FOR ElementorAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
AplazadaMedia (6.4)0.16%—Htmega HT Mega Addons FOR ElementorAI30/9/202630/9/2026
The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.5)0.17%—Leap13 Premium Addons FOR ElementorAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
AplazadaMedia (6.8)0.24%—Happyaddons FOR ElementorAI23/9/202623/9/2026
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the…
AplazadaMedia (6.5)0.28%—WOW Elements Addons FOR ElementorAI19/9/202621/9/2026
The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or…
AplazadaAlta (8.1)0.58%—Master-addons Master Addons FOR ElementorAI18/9/202619/9/2026
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an…
AplazadaMedia (6.1)0.37%—Qodeinteractive QI Addons FOR ElementorAI18/9/202619/9/2026
The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (5.3)0.29%—Kingaddons King Addons FOR ElementorAI17/9/202617/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
AplazadaAlta (7.6)0.38%—Sktthemes SKT Addons FOR ElementorAI17/9/202619/9/2026
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
AplazadaMedia (6.8)0.43%—Htmega HT Mega Addons FOR ElementorAI17/9/202618/9/2026
The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the…
AplazadaAlta (7.6)0.38%—Wowdevs SKY Addons FOR ElementorAI11/9/202611/9/2026
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
AplazadaAlta (7.1)0.32%—Jeweltheme Master Addons FOR ElementorAI11/9/202611/9/2026
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
AplazadaMedia (5.3)0.40%—Wpdeveloper Essential Addons FOR ElementorAI28/8/202628/8/2026
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
AplazadaAlta (7.2)0.27%—Animation Addons FOR ElementorAI19/8/202626/8/2026
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
AplazadaCrítica (9.6)0.43%—Piotnet Addons FOR Elementor PROAI18/8/202620/8/2026
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
AplazadaAlta (8.1)0.38%—Wpdeveloper Essential Addons FOR ElementorAI14/8/202626/8/2026
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a…
AplazadaMedia (6.5)0.22%—Brainstormforce Ultimate Addons FOR ElementorAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
AplazadaMedia (6.4)0.33%—Exclusive Addons FOR ElementorAI2/8/202612/8/2026
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.32%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are…
AplazadaMedia (4.8)0.24%—Wpdeveloper Essential Addons FOR ElementorAI30/7/202630/7/2026
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,…
AplazadaMedia (6.1)0.25%—Animation Addons FOR ElementorAI30/7/202630/7/2026
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.
AplazadaMedia (6.4)0.42%—Brainstormforce Ultimate Addons FOR ElementorAI22/7/202622/7/2026
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.4)0.42%—Wpdeveloper Essential Addons FOR ElementorAI21/7/202623/7/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…