WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.22 Fixed in 2.0.23 CVE-2026-105064 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.109 Fixed in 4.11.110 CVE-2026-103084 Patchstack
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
7.5 High WPCafe Plugin wp-cafe Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting ≤ 3.0.18 CVE-2026-75028 Wordfence
6.3 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Subscriber+ SQLi via get_addon_output_data 1.5.142 – < 2.0.21 Fixed in 2.0.21 CVE-2026-92923 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQLi via 'ucs' Parameter No login needed 1.5.139 – < 2.0.21 Fixed in 2.0.21 CVE-2026-85568 WPScan
6.6 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated Arbitrary File Write via Path Traversal < 2.0.21 Fixed in 2.0.21 CVE-2026-85015 WPScan
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget ≤ 1.3.2 CVE-2025-12828 Wordfence
5.4 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 3.2.19 CVE-2026-100180 Wordfence
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Icon Library Parameter < 2.0.21 Fixed in 2.0.21 CVE-2026-85016 WPScan
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.8.4 Fixed in 6.8.5 CVE-2026-102394 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103063 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103064 Patchstack
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103341 Patchstack
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
6.5 Medium Cool Formkit Lite Plugin extensions-for-elementor-form Cross-Site Scripting ≤ 2.7.8 Fixed in 2.7.9 CVE-2026-97301 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.86 Fixed in 51.1.87 CVE-2026-97298 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.85 Fixed in 51.1.86 CVE-2026-96835 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.5.1 Fixed in 6.5.2 CVE-2026-96829 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.23.1 Fixed in 3.50.0 CVE-2026-62080 Patchstack
6.5 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting ≤ 1.11 Fixed in 1.11.1 CVE-2026-62079 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-62078 Patchstack
6.4 Medium HT Mega Addons for Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting ≤ 3.1.1 CVE-2026-11895 Wordfence
4.3 Medium Image Optimizer by Elementor Plugin Information Disclosure Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks < 1.7.7 Fixed in 1.7.7 CVE-2026-90953 WPScan
6.8 Medium Hostinger Reach Plugin hostinger-reach Cross-Site Scripting Contributor+ Stored XSS via formId Elementor Widget Attribute 1.0.6 – < 1.8.3 Fixed in 1.8.3 CVE-2026-87777 WPScan
6.8 Medium EmbedPress Plugin embedpress Cross-Site Scripting Contributor+ Stored XSS via Elementor Widget showTitle Attribute 4.4.9 – < 4.6.7 Fixed in 4.6.7 CVE-2026-85001 WPScan
7.2 High Repeater Fields for Elementor Forms Plugin repeater-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Field Value No login needed ≤ 2.2.7 CVE-2026-94573 Wordfence
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
7.2 High MasterStudy LMS 3.5.29 Plugin Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget 3.5.29 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88843 WPScan
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-94500 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-94168 Patchstack
8.5 High Live Copy Paste for Elementor Plugin live-copy-paste SQL Injection ≤ 1.5.10 Fixed in 1.5.11 CVE-2026-93527 Patchstack
6.8 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Contributor+ Stored XSS via Creative Button Widget < 3.50.0 Fixed in 3.50.0 CVE-2026-85006 WPScan
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor PHP Object Injection Subscriber+ PHP Object Injection < 2.0.20 Fixed in 2.0.20 CVE-2026-85017 WPScan
6.4 Medium Gum Addon for Elementor Plugin gum-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting ≤ 1.3.15 CVE-2026-8354 Wordfence
6.5 Medium Wow Elements Addons for Elementor Plugin wow-elements-addons-for-elementor Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting No login needed ≤ 1.11.2 CVE-2026-1641 Wordfence
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.16 CVE-2026-18405 Wordfence
8.1 High Master Addons for Elementor Plugin master-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter ≤ 3.2.2 CVE-2026-85410 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
6.1 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 1.11 CVE-2026-92249 Wordfence
3.8 Low King Addons for Elementor Plugin king-addons Broken Access Control Author+ Missing Authorization via Image Optimizer 51.1.56 – < 51.1.81 Fixed in 51.1.81 CVE-2026-84904 WPScan
2.7 Low King Addons for Elementor Plugin king-addons Information Disclosure Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode < 51.1.81 Fixed in 51.1.81 CVE-2026-84903 WPScan
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Template Catalog Import < 51.1.81 Fixed in 51.1.81 CVE-2026-84902 WPScan
7.6 High SKT Addons for Elementor Plugin skt-addons-for-elementor SQL Injection ≤ 4.0 Fixed in 4.1 CVE-2026-66626 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only