Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.13%—Kingaddons King AddonsAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
AplazadaMedia (6.5)0.16%—Kingaddons King AddonsAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
AplazadaBaja (3.8)0.26%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with…
AplazadaBaja (2.7)0.32%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they…
AplazadaMedia (6.8)0.43%—Kingaddons King AddonsAI18/9/202618/9/2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by…
AplazadaMedia (5.3)0.29%—Kingaddons King Addons FOR ElementorAI17/9/202617/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
AplazadaMedia (6.8)0.43%—Kingaddons King AddonsAI5/9/20268/9/2026
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in…
AplazadaMedia (6.1)0.25%—Kingaddons King AddonsAI2/8/202626/8/2026
The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.
AplazadaMedia (6.4)0.42%—Kingaddons King AddonsAI10/7/202610/7/2026
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves…
AplazadaMedia (6.5)0.22%—Kingaddons King Addons FOR ElementorAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.
AplazadaMedia (6.4)0.24%—Kingaddons King AddonsAI1/4/202630/9/2026
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses…
AplazadaMedia (5.3)0.22%—Kingaddons King AddonsAI23/3/202617/6/2026
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via render_full_form…
AplazadaMedia (6.4)0.18%—Kingaddons King AddonsAI13/12/202517/6/2026
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This…
AplazadaCrítica (10)0.47%—Kingaddons King Addons FOR ElementorAI6/11/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a Web Server.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.
AplazadaCrítica (9.8)0.40%—Kingaddons King AddonsAI6/11/202517/6/2026
Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.
AplazadaCrítica (9.8)9.6%—Kingaddons King AddonsAI31/10/202517/6/2026
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for…
AplazadaMedia (6.5)0.32%—Kingaddons King Addons FOR ElementorAI27/10/202517/6/2026
Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.
AplazadaMedia (6.5)0.21%—Kingaddons King Addons FOR ElementorAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com King Addons for Elementor king-addons allows DOM-Based XSS.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.
AplazadaMedia (4.3)0.31%—Kingaddons King AddonsAI1/4/202517/6/2026
Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons.This issue affects King Addons for Elementor: from n/a through <= 24.12.58.