Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.5)0.24%—Unlimited-elements Unlimited Elements FOR ElementorAI5/10/20265/10/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,…
RecibidaCrítica (9.3)0.25%—Unlimited-elements Unlimited Elements FOR ElementorAI4/10/20266/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,…
RecibidaAlta (7.1)0.15%—Unlimited-elements Unlimited Elements FOR ElementorAI4/10/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
RecibidaAlta (7.1)0.15%—Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
RecibidaMedia (6.3)0.18%—Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level…
RecibidaMedia (6.8)0.22%—Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default.
RecibidaMedia (6.6)0.42%—Unlimited-elements Unlimited Elements FOR ElementorAI3/10/20263/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress…
AplazadaMedia (5.4)0.18%—Unlimited-elements Unlimited Elements FOR ElementorAI2/10/20262/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level…
AplazadaMedia (6.8)0.24%—Unlimited-elements Unlimited Elements FOR ElementorAI2/10/20262/10/2026
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
AplazadaMedia (5.3)0.19%—Unlimited-elements Unlimited Elements FOR ElementorAI1/10/20261/10/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…
AplazadaAlta (8.5)0.21%—Unlimited-elements Unlimited Elements FOR ElementorAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,…
AplazadaAlta (7.5)0.40%—Unlimited-elements Unlimited Elements FOR ElementorAI20/9/202621/9/2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the…
AplazadaMedia (6.4)0.23%—Unlimited-elements Unlimited Elements FOR ElementorAI17/9/202617/9/2026
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
AplazadaMedia (6.1)0.45%—Unlimited-elements Unlimited Elements FOR ElementorAI11/9/202611/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.5)0.33%—Unlimited-elements Unlimited Elements FOR ElementorAI11/9/202611/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString()…
AplazadaAlta (7.1)0.25%—Unlimited-elements Unlimited Elements FOR ElementorAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
AplazadaMedia (6.1)0.38%—Unlimited-elements Unlimited Elements FOR ElementorAI5/9/20268/9/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.31%—Unlimited-elements Unlimited Elements FOR ElementorAI3/9/20263/9/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
AplazadaMedia (6.5)0.44%—Unlimited-elements Unlimited Elements FOR ElementorAI6/8/202612/8/2026
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
AplazadaMedia (5.4)0.29%—Unlimited-elements Unlimited Elements FOR ElementorAI3/8/202612/8/2026
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
AplazadaAlta (8.8)0.51%—Unlimited-elements Unlimited Elements FOR ElementorAI20/7/202621/7/2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver…
AplazadaAlta (7.1)0.25%—Unlimited-elements Unlimited Elements FOR ElementorAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
AplazadaCrítica (9.9)0.48%—Unlimited-elements Unlimited Elements FOR ElementorAI17/6/202617/6/2026
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
AplazadaAlta (8.5)0.36%—Unlimited-elements Unlimited Elements FOR ElementorAI25/5/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
AplazadaMedia (6.5)0.55%—Unlimited-elements Unlimited ElementsAI14/5/202617/6/2026
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the use of deprecated escaping functions combined with direct…