Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level…
RecibidaSin puntuar——Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
RecibidaSin puntuar——Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress…
AplazadaMedia (5.4)0.18%—Unlimited-elements Unlimited Elements FOR ElementorAI2/10/20262/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level…
AplazadaMedia (6.8)0.15%—Unlimited-elements Unlimited Elements FOR ElementorAI2/10/20262/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
AplazadaMedia (5.3)0.19%—Unlimited-elements Unlimited Elements FOR ElementorAI1/10/20261/10/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…
AplazadaAlta (8.5)0.21%—Unlimited-elements Unlimited Elements FOR ElementorAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,…
AplazadaMedia (6.5)0.13%—Wpmet Elementskit LiteAI1/10/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
AplazadaMedia (6.5)0.13%—Wpmet Elementskit LiteAI1/10/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
AplazadaMedia (6.5)0.17%—Wpmet Elementskit Elementor AddonsAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
AplazadaAlta (7.5)0.40%—Unlimited-elements Unlimited Elements FOR ElementorAI20/9/202621/9/2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the…
AplazadaMedia (6.5)0.28%—WOW Elements Addons FOR ElementorAI19/9/202621/9/2026
The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or…
AplazadaMedia (6.4)0.23%—Unlimited-elements Unlimited Elements FOR ElementorAI17/9/202617/9/2026
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
AplazadaMedia (6.1)0.45%—Unlimited-elements Unlimited Elements FOR ElementorAI11/9/202611/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.5)0.33%—Unlimited-elements Unlimited Elements FOR ElementorAI11/9/202611/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString()…
AplazadaAlta (7.1)0.25%—Unlimited-elements Unlimited Elements FOR ElementorAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
AplazadaMedia (6.1)0.38%—Unlimited-elements Unlimited Elements FOR ElementorAI5/9/20268/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.31%—Unlimited-elements Unlimited Elements FOR ElementorAI3/9/20263/9/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
AplazadaMedia (6.1)0.38%—Elementskit PROAI28/8/202628/8/2026
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions up to, and including, 4.10.1 due to insufficient input sanitization and output escaping. The REST endpoint at /wp-json/elementskit/v1/advanced-search uses…
AplazadaMedia (6.5)0.44%—Unlimited-elements Unlimited Elements FOR ElementorAI6/8/202612/8/2026
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
AplazadaMedia (5.4)0.29%—Unlimited-elements Unlimited Elements FOR ElementorAI3/8/202612/8/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
AplazadaBaja (3.5)0.24%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious…
AplazadaAlta (7.2)0.66%—Wpmet Elementskit Elementor AddonsAI31/7/202626/8/2026
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing…
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.