Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
225 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Wpmet Elementskit Elementor AddonsAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Element Pack Elementor AddonsAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | |
| Aplazada | Media (5.4) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/9/2026 | 16/9/2026 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Hashthemes Easy Elementor AddonsAI | 20/8/2026 | 24/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | |
| Aplazada | Alta (8.8) | 0.63% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/8/2026 | 20/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render… | |
| Aplazada | Media (5.3) | 0.33% | — | Element Pack Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Ultimate Store KIT Elementor AddonsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Baja (3.5) | 0.24% | — | Wpmet Elementskit Elementor AddonsAI | 31/7/2026 | 26/8/2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious… | |
| Aplazada | Alta (7.2) | 0.66% | — | Wpmet Elementskit Elementor AddonsAI | 31/7/2026 | 26/8/2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing… | |
| Aplazada | Media (5.3) | 0.33% | — | Ultimate Store KIT Elementor AddonsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Ultimate Store KIT Elementor AddonsAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | |
| Aplazada | Media (4.3) | 0.35% | — | Themeum Tutor LMS Elementor AddonsAI | 21/7/2026 | 22/7/2026 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | |
| Aplazada | Media (6.4) | 0.43% | — | Prime Elementor AddonsAI | 9/6/2026 | 23/7/2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.31% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (6.5) | 0.28% | — | Xpro Elementor Addons PROAI | 27/5/2026 | 30/9/2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.32% | — | Royal-elementor-addons Royal Elementor AddonsAI | 14/5/2026 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Alta (8.5) | 0.36% | — | Xpro Elementor AddonsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (5.3) | 0.31% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Alta (7.2) | 0.42% | — | Royal-elementor-addons Royal Elementor AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked… | |
| Aplazada | Alta (7.2) | 0.48% | — | Royal-elementor-addons Royal Elementor AddonsAI | 2/5/2026 | 18/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query… | |
| Aplazada | Media (6.4) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 24/4/2026 | 14/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of… | |
| Aplazada | Media (5.3) | 0.29% | — | Royal Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056. |