Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Kingaddons King AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Kingaddons King AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | |
| Aplazada | Baja (3.8) | 0.26% | — | Kingaddons King AddonsAI | 18/9/2026 | 18/9/2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with… | |
| Aplazada | Baja (2.7) | 0.32% | — | Kingaddons King AddonsAI | 18/9/2026 | 18/9/2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they… | |
| Aplazada | Media (6.8) | 0.43% | — | Kingaddons King AddonsAI | 18/9/2026 | 18/9/2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by… | |
| Aplazada | Media (5.3) | 0.29% | — | Kingaddons King Addons FOR ElementorAI | 17/9/2026 | 17/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Kingaddons King AddonsAI | 5/9/2026 | 8/9/2026 | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in… | |
| Aplazada | Media (6.1) | 0.25% | — | Kingaddons King AddonsAI | 2/8/2026 | 26/8/2026 | The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page. | |
| Aplazada | Media (6.4) | 0.42% | — | Kingaddons King AddonsAI | 10/7/2026 | 10/7/2026 | The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves… | |
| Aplazada | Media (6.5) | 0.22% | — | Kingaddons King Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions. | |
| Aplazada | Media (6.4) | 0.24% | — | Kingaddons King AddonsAI | 1/4/2026 | 30/9/2026 | The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses… | |
| Aplazada | Media (5.3) | 0.22% | — | Kingaddons King AddonsAI | 23/3/2026 | 17/6/2026 | The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via render_full_form… | |
| Aplazada | Media (6.4) | 0.18% | — | Kingaddons King AddonsAI | 13/12/2025 | 17/6/2026 | The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Crítica (10) | 0.47% | — | Kingaddons King Addons FOR ElementorAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a Web Server.This issue affects King Addons for Elementor: from n/a through <= 51.1.36. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Kingaddons King AddonsAI | 6/11/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects King Addons for Elementor: from n/a through <= 51.1.36. | |
| Aplazada | Crítica (9.8) | 9.6% | — | Kingaddons King AddonsAI | 31/10/2025 | 17/6/2026 | The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.32% | — | Kingaddons King Addons FOR ElementorAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.61. | |
| Aplazada | Media (6.5) | 0.21% | — | Kingaddons King Addons FOR ElementorAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com King Addons for Elementor king-addons allows DOM-Based XSS.This issue affects King Addons for Elementor: from n/a through <= 51.1.61. | |
| Aplazada | Media (4.3) | 0.31% | — | Kingaddons King AddonsAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons.This issue affects King Addons for Elementor: from n/a through <= 24.12.58. |