Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Wpdeveloper Essential Addons FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | |
| Aplazada | Media (5.3) | 0.40% | — | Wpdeveloper Essential Addons FOR ElementorAI | 28/8/2026 | 28/8/2026 | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. | |
| Aplazada | Alta (8.1) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/8/2026 | 26/8/2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are… | |
| Aplazada | Media (4.8) | 0.24% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper Essential Addons FOR ElementorAI | 21/7/2026 | 22/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.67% | — | Wpdeveloper Essential Addons FOR ElementorAI | 11/7/2026 | 15/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct… | |
| Aplazada | Media (6.4) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 8/7/2026 | 8/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | |
| Aplazada | Media (5.3) | 0.56% | — | Wpdeveloper Essential Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.31% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it… | |
| Aplazada | Media (5.3) | 0.24% | — | Wpdeveloper Essential Addons FOR Elementor LiteAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5. | |
| Aplazada | Media (6.4) | 0.25% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/2/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 16/1/2026 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft,… | |
| Analizada | Media (6.5) | 0.15% | — | Wpdeveloper Essential Addons FOR Elementor | 30/12/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3. | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdeveloper Essential Addons FOR ElementorAI | 17/12/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom… | |
| Modificada | Baja (2.7) | 0.23% | — | Wpdeveloper Essential Addons FOR Elementor | 31/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4. | |
| Aplazada | Media (6.4) | 0.24% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/8/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Analizada | Media (5.4) | 0.18% | — | Wpdeveloper Essential Addons FOR Elementor | 8/7/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This… | |
| Analizada | Media (5.4) | 0.20% | — | Wpdeveloper Essential Addons FOR Elementor | 7/6/2025 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient… | |
| Analizada | Media (5.4) | 0.20% | — | Wpdeveloper Essential Addons FOR Elementor | 7/6/2025 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input… | |
| Modificada | Media (6.1) | 1.2% | — | Wpdeveloper Essential Addons FOR Elementor | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.14. | |
| Modificada | Media (6.5) | 0.32% | — | Wpdeveloper Essential Addons FOR Elementor | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9. | |
| Modificada | Media (4.3) | 0.42% | — | Wpdeveloper Essential Addons FOR Elementor | 16/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9. |