Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

225 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Wpmet Elementskit Elementor AddonsAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
AplazadaMedia (6.5)0.22%—Element Pack Elementor AddonsAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
AplazadaMedia (5.4)0.22%—Royal-elementor-addons Royal Elementor AddonsAI16/9/202616/9/2026
The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on…
AplazadaCrítica (9.6)0.20%—Hashthemes Easy Elementor AddonsAI20/8/202624/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
AplazadaAlta (8.8)0.63%—Royal-elementor-addons Royal Elementor AddonsAI16/8/202620/8/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render…
AplazadaMedia (5.3)0.33%—Element Pack Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
AplazadaMedia (6.5)0.27%—Ultimate Store KIT Elementor AddonsAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaBaja (3.5)0.24%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious…
AplazadaAlta (7.2)0.66%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing…
AplazadaMedia (5.3)0.33%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (6.5)0.22%—Ultimate Store KIT Elementor AddonsAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
AplazadaMedia (4.3)0.35%—Themeum Tutor LMS Elementor AddonsAI21/7/202622/7/2026
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for…
AplazadaAlta (7.1)0.25%—Royal-elementor-addons Royal Elementor Addons PROAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
AplazadaMedia (6.4)0.43%—Prime Elementor AddonsAI9/6/202623/7/2026
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.3)0.31%—Wpmet Elementskit Elementor Addons LiteAI27/5/202617/6/2026
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
AplazadaMedia (4.3)0.25%—Wpmet Elementskit Elementor Addons LiteAI27/5/202617/6/2026
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
AplazadaMedia (6.5)0.28%—Xpro Elementor Addons PROAI27/5/202630/9/2026
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can…
AplazadaMedia (6.4)0.32%—Royal-elementor-addons Royal Elementor AddonsAI14/5/202617/6/2026
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaAlta (8.5)0.36%—Xpro Elementor AddonsAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1.
AplazadaMedia (6.5)0.22%—Royal-elementor-addons Royal Elementor AddonsAI7/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.
AplazadaMedia (5.3)0.31%—Royal-elementor-addons Royal Elementor AddonsAI7/5/202617/6/2026
Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.
AplazadaAlta (7.2)0.42%—Royal-elementor-addons Royal Elementor AddonsAI5/5/202617/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked…
AplazadaAlta (7.2)0.48%—Royal-elementor-addons Royal Elementor AddonsAI2/5/202618/8/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query…
AplazadaMedia (6.4)0.35%—Royal-elementor-addons Royal Elementor AddonsAI24/4/202614/8/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of…
AplazadaMedia (5.3)0.29%—Royal Elementor AddonsAI15/4/202617/6/2026
Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056.