Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/9/2026 | 16/9/2026 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on… | |
| Aplazada | Media (5.3) | 0.32% | — | Royal AddonsAI | 12/9/2026 | 14/9/2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all… | |
| Aplazada | Media (6.8) | 0.23% | — | Royal AddonsAI | 26/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.24% | — | Royal AddonsAI | 26/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies. | |
| Aplazada | Media (5.3) | 0.22% | — | Royal AddonsAI | 26/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post,… | |
| Aplazada | Media (6.6) | 0.38% | — | Royal AddonsAI | 20/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution… | |
| Aplazada | Alta (8.8) | 0.63% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/8/2026 | 20/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render… | |
| Aplazada | Media (5.4) | 0.23% | — | Royal AddonsAI | 12/8/2026 | 26/8/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.34% | — | Royaladdons Royal Addons FOR ElementorAI | 17/7/2026 | 17/7/2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu… | |
| Aplazada | Alta (8.1) | 0.43% | — | Royal MCPAI | 1/7/2026 | 1/7/2026 | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content… | |
| Aplazada | Alta (8.1) | 0.35% | — | Royal Plugins Royal MCPAI | 25/6/2026 | 25/6/2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. | |
| Aplazada | Media (6.5) | 0.39% | — | Royal AddonsAI | 19/6/2026 | 22/6/2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable()… | |
| Aplazada | Alta (7.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | |
| Aplazada | Alta (7.3) | 0.30% | — | Royal MCPAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Royal-elementor-addons Royal Elementor AddonsAI | 14/5/2026 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (5.3) | 0.31% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (6.4) | 0.36% | — | Royal AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.2) | 0.42% | — | Royal-elementor-addons Royal Elementor AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked… | |
| Aplazada | Media (5.3) | 0.46% | — | Royal AddonsAI | 2/5/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it… | |
| Aplazada | Alta (7.2) | 0.48% | — | Royal-elementor-addons Royal Elementor AddonsAI | 2/5/2026 | 18/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query… | |
| Aplazada | Media (6.4) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 24/4/2026 | 14/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of… | |
| Aplazada | Media (6.4) | 0.33% | — | Royal AddonsAI | 17/4/2026 | 17/6/2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.29% | — | Royal Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056. | |
| Aplazada | Media (6.1) | 0.35% | — | Royal Wordpress Backup Restore PluginAI | 10/4/2026 | 17/6/2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web… |