WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–25 of 25 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Typing Effect Plugin animated-typing-effect Cross-Site Scripting ≤ 1.3.7 CVE-2026-66644 Patchstack
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting ≤ 1.0.21 CVE-2026-11380 Wordfence
6.4 Medium Animate Your Content Plugin animate-your-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.0 CVE-2026-8872 Wordfence
4.3 Medium Animated Pixel Marquee Creator Plugin animated-pixel-marquee-creator Cross-Site Request Forgery Cross-Site Request Forgery via 'marquee' Parameter No login needed ≤ 1.0.0 CVE-2025-14062 Wordfence
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Field ≤ 1.1.9 CVE-2025-9077 Wordfence
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks ≤ 3.1.0 CVE-2025-7727 Wordfence
6.4 Medium Animated Buttons Plugin animated-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-4221 Wordfence
4.9 Medium Animate Plugin animate Server-Side Request Forgery ≤ 0.5 CVE-2025-46443 Patchstack
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets ≤ 2.7.6 CVE-2025-1571 Wordfence
6.5 Medium Animated Text Block Plugin animated-text-block Broken Access Control ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26883 Patchstack
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
4.3 Medium Animated Rotating Words Plugin css3-rotating-words Cross-Site Request Forgery No login needed ≤ 5.6 Fixed in 5.7 CVE-2024-38753 Patchstack
5.4 Medium Animated Rotating Words Plugin css3-rotating-words Broken Access Control ≤ 5.4 Fixed in 5.5 CVE-2023-47187 Patchstack
6.4 Medium Animated Counters Plugin animated-counters Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-11905 Wordfence
7.1 High Go Animate Plugin goanimate Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54397 Patchstack
6.4 Medium Counter Up – Animated Number Counter & Milestone Showcase Plugin Cross-Site Scripting Animated Number Counter & Milestone Showcase <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2024-10895 Wordfence
6.4 Medium R Animated Icon Plugin r-animated-icon Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9272 Wordfence
6.5 Medium Animated Number Counters Plugin animated-number-counters Local File Inclusion Editor+ Limited Local File Inclusion ≤ 1.9 CVE-2024-43957 Patchstack
6.5 Medium Animated Typed JS Shortcode Plugin animated-typed-js-shortcode Cross-Site Scripting ≤ 2.0 CVE-2024-38679 Patchstack
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
5.4 Medium Animated AL List Plugin animated-al-list Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.6 CVE-2024-5728 WPScan
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget ≤ 1.0.15 CVE-2024-2138 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget ≤ 8.3.4 CVE-2024-1458 Wordfence
6.5 Medium Lordicon Animated Icons Plugin lordicon-interactive-icons Cross-Site Scripting ≤ 2.0.1 CVE-2024-30519 Patchstack
6.4 Medium Animated Headline Plugin animated-headline Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.0 CVE-2024-2304 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only