Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/9/2026 | 16/9/2026 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on… | |
| Aplazada | Alta (8.8) | 0.63% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/8/2026 | 20/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render… | |
| Aplazada | Alta (7.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Royal-elementor-addons Royal Elementor AddonsAI | 14/5/2026 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.22% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Media (5.3) | 0.31% | — | Royal-elementor-addons Royal Elementor AddonsAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053. | |
| Aplazada | Alta (7.2) | 0.42% | — | Royal-elementor-addons Royal Elementor AddonsAI | 5/5/2026 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked… | |
| Aplazada | Alta (7.2) | 0.48% | — | Royal-elementor-addons Royal Elementor AddonsAI | 2/5/2026 | 18/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query… | |
| Aplazada | Media (6.4) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 24/4/2026 | 14/8/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of… | |
| Aplazada | Media (5.3) | 0.29% | — | Royal Elementor AddonsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056. | |
| Aplazada | Alta (8.2) | 0.43% | — | Royal Elementor AddonsAI | 5/3/2026 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1052. | |
| Aplazada | Media (6.4) | 0.18% | — | Royal-elementor-addons Royal Elementor AddonsAI | 19/11/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Modificada | Media (5.4) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons | 26/6/2025 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons | 31/5/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.26% | — | Royal-elementor-addons Royal Elementor Addons | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1017. | |
| Analizada | Media (5.4) | 0.28% | — | Royal-elementor-addons Royal Elementor Addons | 7/5/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.35% | — | Royal-elementor-addons Royal Elementor AddonsAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.3.977. | |
| Modificada | Media (4.9) | 0.22% | — | Royal-elementor-addons Royal Elementor Addons | 15/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1006. | |
| Analizada | Media (5.4) | 0.28% | — | Royal-elementor-addons Royal Elementor Addons | 12/4/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (5.4) | 0.28% | — | Royal-elementor-addons Royal Elementor Addons | 12/4/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Alta (8.8) | 0.22% | — | Royal-elementor-addons Royal Elementor Addons | 19/2/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (6.1) | 0.23% | — | Royal-elementor-addons Royal Elementor Addons | 14/1/2025 | 17/6/2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (5.4) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.3.987. | |
| Modificada | Media (4.3) | 0.28% | — | Royal-elementor-addons Royal Elementor Addons | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1001. | |
| Modificada | Media (6.1) | 0.28% | — | Royal-elementor-addons Royal Elementor Addons | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Reflected XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1001. |