WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–36 of 36 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack
6.8 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes < 8.7.13 Fixed in 8.7.13 CVE-2026-14817 WPScan
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Request Forgery No login needed ≤ 8.3.13 Fixed in 8.3.14 CVE-2025-31413 Patchstack
5.4 Medium Element Pack Elementor Addons and Templates Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content ≤ 8.1.5 CVE-2025-8100 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.10.29 CVE-2025-1458 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.28 CVE-2025-1457 Wordfence
4.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Broken Access Control Missing Authorization ≤ 5.10.12 CVE-2024-11852 Wordfence
6.4 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget ≤ 5.10.5 CVE-2024-9058 Wordfence
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10980 WPScan
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10493 WPScan
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget ≤ 5.10.2 CVE-2024-9867 Wordfence
6.5 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.2 CVE-2024-9657 Wordfence
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.10.1 CVE-2024-9868 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.7.5 Fixed in 5.7.6 CVE-2024-47392 Patchstack
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets ≤ 5.7.2 CVE-2024-7247 Wordfence
6.5 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 5.7.2 CVE-2024-4359 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag ≤ 5.7.6 CVE-2024-4360 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.11 CVE-2024-4643 Wordfence
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.6.11 Fixed in 5.6.12 CVE-2024-39667 Patchstack
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.5 CVE-2024-5555 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.11 CVE-2024-5554 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events ≤ 5.6.11 CVE-2024-3925 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes ≤ 5.6.1 CVE-2024-3926 Wordfence
5.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Other Form Submission Admin Email Bypass No login needed ≤ 5.6.3 CVE-2024-3927 Wordfence
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.6.0 Fixed in 5.6.1 CVE-2024-32572 Patchstack
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget ≤ 5.6.0 CVE-2024-1429 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget ≤ 5.6.0 CVE-2024-1426 Wordfence
5.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Information Disclosure Sensitive Information Exposure via element_pack_ajax_search No login needed ≤ 5.5.6 CVE-2024-2966 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
8.5 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30496 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30185 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 5.4.11 Fixed in 5.4.12 CVE-2024-24840 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only