WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 190 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
7.5 High WPCafe Plugin wp-cafe Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting ≤ 3.0.18 CVE-2026-75028 Wordfence
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
7.2 High Repeater Fields for Elementor Forms Plugin repeater-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Field Value No login needed ≤ 2.2.7 CVE-2026-94573 Wordfence
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
7.2 High MasterStudy LMS 3.5.29 Plugin Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget 3.5.29 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88843 WPScan
8.5 High Live Copy Paste for Elementor Plugin live-copy-paste SQL Injection ≤ 1.5.10 Fixed in 1.5.11 CVE-2026-93527 Patchstack
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor PHP Object Injection Subscriber+ PHP Object Injection < 2.0.20 Fixed in 2.0.20 CVE-2026-85017 WPScan
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.16 CVE-2026-18405 Wordfence
8.1 High Master Addons for Elementor Plugin master-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter ≤ 3.2.2 CVE-2026-85410 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
7.6 High SKT Addons for Elementor Plugin skt-addons-for-elementor SQL Injection ≤ 4.0 Fixed in 4.1 CVE-2026-66626 Patchstack
7.1 High Master Addons for Elementor Plugin master-addons Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-62089 Patchstack
7.6 High Sky Addons for Elementor Plugin sky-elementor-addons SQL Injection ≤ 3.8.4 Fixed in 3.8.5 CVE-2026-62109 Patchstack
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.16 CVE-2026-18561 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
7.1 High RTMKit Plugin rometheme-for-elementor Cross-Site Scripting No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84763 Patchstack
8.8 High RTMKit Plugin rometheme-for-elementor PHP Object Injection ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84752 Patchstack
7.2 High Master Addons for Elementor Plugin master-addons Broken Access Control Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction ≤ 3.1.9 CVE-2026-75921 Wordfence
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-32473 Patchstack
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting ≤ 1.7.1064 CVE-2026-17123 Wordfence
8.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment No login needed 5.8.6 – < 6.7.2 Fixed in 6.7.2 CVE-2026-18039 WPScan
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit PHP Object Injection ≤ 3.2.10 Fixed in 3.2.11 CVE-2026-65549 Patchstack
8.8 High DynamicKit for Elementor Plugin dynamickit-elementor Privilege Escalation Unauthenticated Account Takeover via Password Reset Link Host Injection No login needed < 1.0.3 Fixed in 1.0.3 CVE-2026-14596 WPScan
7.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Cross-Site Scripting Reflected XSS via form_id No login needed < 1.5.3 Fixed in 1.5.3 CVE-2026-14870 WPScan
7.1 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65488 Patchstack
8.8 High CRT Addons for Elementor Plugin Cross-Site Scripting Unauthenticated Stored XSS via Contact Form No login needed < 1.6.7 Fixed in 1.6.7 CVE-2026-11767 WPScan
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-10081 WPScan
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-57804 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.12 Fixed in 2.0.13 CVE-2026-57718 Patchstack
7.1 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-57376 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Authenticated (Contributor+) Account Takeover via Email Header Injection ≤ 6.6.10 CVE-2026-15155 Wordfence
7.5 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting ≤ 1.6.1 CVE-2026-15338 Wordfence
8.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed ≤ 1.5.1 CVE-2026-9843 Wordfence
7.1 High Royal Elementor Addons Pro Plugin wpr-addons-pro Cross-Site Scripting No login needed < 1.7.1041 Fixed in 1.7.1041 CVE-2026-40720 Patchstack
8.8 High PowerPack Pro for Elementor Plugin powerpack-elements Authentication Bypass Broken Authentication No login needed < v2.13.0 Fixed in 2.13.0 CVE-2026-42629 Patchstack
7.1 High WPZOOM Addons for Elementor Plugin wpzoom-elementor-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-39597 Patchstack
7.1 High Product Filter Widget for Elementor Plugin product-filter-widget-for-elementor Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2026-45437 Patchstack
8.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-48837 Patchstack
8.8 High Easy Elements for Elementor – Addons & Website Templates Plugin easy-elements Privilege Escalation Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter ≤ 1.4.5 CVE-2026-9018 Wordfence
8.8 High RTMKit Addons for Elementor Plugin rometheme-for-elementor Local File Inclusion Authenticated (Author+) Local File Inclusion via 'path' ≤ 2.0.2 CVE-2026-3425 Wordfence
8.5 High Xpro Elementor Addons Plugin xpro-elementor-addons SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-45214 Patchstack
7.2 High Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta No login needed ≤ 1.7.1056 CVE-2026-4803 Wordfence
7.2 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter No login needed ≤ 1.7.1057 CVE-2026-6229 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only