Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
1937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):… | |
| Aplazada | Alta (8.5) | — | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Media (6.5) | — | — | Wpmet Elementskit LiteAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | |
| Aplazada | Media (6.5) | — | — | Wpmet Elementskit LiteAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | |
| Aplazada | Media (6.5) | — | — | Wpdeveloper Essential Addons FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | |
| Aplazada | Alta (7.2) | — | — | Lastudio Element KITAI | 1/10/2026 | 1/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Qodeinteractive QI Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Leap13 Premium Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Htmega HT Mega Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (8.8) | 0.13% | — | ElementorAI | 25/9/2026 | 25/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Wpmet Elementskit Elementor AddonsAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Leap13 Premium Addons FOR ElementorAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Happyaddons FOR ElementorAI | 23/9/2026 | 23/9/2026 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the… | |
| Aplazada | Alta (7.5) | 0.40% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/9/2026 | 21/9/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the… | |
| Aplazada | Media (6.5) | 0.28% | — | WOW Elements Addons FOR ElementorAI | 19/9/2026 | 21/9/2026 | The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or… | |
| Aplazada | Alta (8.1) | 0.58% | — | Master-addons Master Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an… | |
| Aplazada | Media (6.1) | 0.37% | — | Qodeinteractive QI Addons FOR ElementorAI | 18/9/2026 | 19/9/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.6) | 0.38% | — | Sktthemes SKT Addons FOR ElementorAI | 17/9/2026 | 19/9/2026 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | |
| Aplazada | Media (6.4) | 0.23% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Motopress Jetblocks FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Kingaddons King Addons FOR ElementorAI | 17/9/2026 | 17/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Element Pack Elementor AddonsAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Htmega HT Mega Addons FOR ElementorAI | 17/9/2026 | 18/9/2026 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the… |