Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Element Pack Elementor AddonsAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Element Pack Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | |
| Aplazada | Media (5.3) | 0.35% | — | Element Pack AddonsAI | 6/8/2026 | 12/8/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email… | |
| Aplazada | Media (6.8) | 0.43% | — | Elementpack Element Pack AddonsAI | 2/8/2026 | 26/8/2026 | The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes… | |
| Aplazada | Alta (7.5) | 0.43% | — | Element Pack PROAI | 17/6/2026 | 17/6/2026 | Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Bdthemes Element Pack Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2. | |
| Aplazada | Media (6.4) | 0.36% | — | Bdthemes Element PackAI | 8/4/2026 | 25/7/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. The function… | |
| Aplazada | Media (6.5) | 0.32% | — | Elementpack Element Pack AddonsAI | 15/2/2026 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.3) | 0.16% | — | Bdthemes Element Pack Elementor AddonsAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Cross Site Request Forgery.This issue affects Element Pack Elementor Addons: from n/a through <= 8.3.13. | |
| Aplazada | Media (5.4) | 0.17% | — | Wpastra Element Pack AddonsAI | 18/11/2025 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render… | |
| Aplazada | Media (5) | 0.24% | — | Elementpack Element Pack AddonsAI | 20/10/2025 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to… | |
| Analizada | Media (5.4) | 4.1% | — | Bdthemes Element Pack | 6/8/2025 | 17/6/2026 | The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.30% | — | Bdthemes Element Pack | 3/7/2025 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (5.4) | 0.21% | — | Bdthemes Element Pack PROAI | 5/6/2025 | 17/6/2026 | Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Element Pack Pro: from n/a before 8.0.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Bdthemes Element Pack PROAI | 5/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. | |
| Aplazada | Media (6.4) | 0.21% | — | Bdthemes Element PackAI | 31/5/2025 | 17/6/2026 | The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content’ parameter in all versions up to, and including, 5.11.2 due to insufficient input sanitization and output… | |
| Analizada | Media (5.4) | 0.22% | — | Bdthemes Element Pack | 26/4/2025 | 17/6/2026 | The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insufficient input… | |
| Aplazada | Media (6.4) | 0.32% | — | Bdevs Element Pack AddonsAI | 19/4/2025 | 17/6/2026 | The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping.… | |
| Analizada | Media (5.4) | 0.29% | — | Bdthemes Element Pack | 8/1/2025 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5.10.14 due to insufficient input… | |
| Analizada | Media (4.3) | 0.36% | — | Bdthemes Element Pack | 22/12/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes it possible for… | |
| Analizada | Media (5.4) | 0.24% | — | Bdthemes Element Pack | 3/12/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (5.4) | 0.36% | — | Bdthemes Element Pack | 29/11/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the… | |
| Analizada | Media (5.4) | 0.36% | — | Bdthemes Element Pack | 28/11/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and… | |
| Analizada | Media (5.4) | 0.26% | — | Bdthemes Element Pack | 5/11/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output… | |
| Analizada | Media (5.4) | 0.34% | — | Bdthemes Element Pack | 5/11/2024 | 17/6/2026 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes… |