WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 56 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
9.8 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'type' Parameter No login needed ≤ 1.6.0 CVE-2026-18351 Wordfence
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
9.3 Critical TheGem (Elementor) Theme thegem-elementor SQL Injection No login needed ≤ 5.12.3 Fixed in 5.12.3.1 CVE-2026-66609 Patchstack
9.0 Critical Elementor Pro Plugin elementor-pro Arbitrary File Upload No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-32475 Patchstack
9.6 Critical Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Arbitrary File Upload No login needed ≤ 7.1.67 CVE-2026-28192 Patchstack
9.8 Critical Easy Elements for Elementor – Addons & Website Templates Plugin easy-elements Privilege Escalation Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-56028 Patchstack
9.9 Critical Unlimited Elements for Elementor (Premium) Plugin unlimited-elements-for-elementor-premium Arbitrary File Upload ≤ 2.0.6 CVE-2026-27041 Patchstack
9.8 Critical Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp PHP Object Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2026-49765 Patchstack
9.8 Critical Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-49109 Patchstack
9.8 Critical WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49105 Patchstack
9.8 Critical Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-infusionsoft PHP Object Injection No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2026-49104 Patchstack
9.8 Critical WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49085 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
9.8 Critical Easy Elements for Elementor Plugin easy-elements Privilege Escalation Unauthenticated Privilege Escalation via easyel_handle_register No login needed ≤ 1.4.4 CVE-2026-7284 Wordfence
9.8 Critical Piotnet Addons for Elementor Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Form File Upload No login needed ≤ 7.1.70 CVE-2026-4885 Wordfence
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via 'download_csv' No login needed ≤ 1.4.7 CVE-2026-2599 Wordfence
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
10.0 Critical ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor Plugin elementskit-lite Broken Access Control ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint No login needed < 3.7.9 Fixed in 3.7.9 CVE-2026-23693 VulnCheck
9.3 Critical Download Manager Addons for Elementor Plugin wpdm-elementor SQL Injection No login needed ≤ 1.3.0 Fixed in 2.0.0 CVE-2026-24956 Patchstack
9.8 Critical Themesflat Elementor Plugin themesflat-elementor PHP Object Injection No login needed ≤ 1.0.1 CVE-2025-69382 Patchstack
9.1 Critical Xpro Elementor Addons Plugin xpro-elementor-addons Arbitrary File Upload ≤ 1.4.19.1 Fixed in 1.4.20 CVE-2025-69312 Patchstack
9.8 Critical LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Privilege Escalation Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter No login needed ≤ 1.5.6.3 CVE-2026-0920 Wordfence
10.0 Critical King Addons for Elementor Plugin king-addons Arbitrary File Upload No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6327 Patchstack
9.8 Critical King Addons for Elementor Plugin king-addons Privilege Escalation No login needed ≤ 51.1.36 Fixed in 51.1.37 CVE-2025-6325 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Arbitrary File Upload ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-62065 Patchstack
9.8 Critical King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor Plugin king-addons Privilege Escalation Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation No login needed ≤ 51.1.14 CVE-2025-8489 Wordfence
9.8 Critical TF Woo Product Grid Addon For Elementor Plugin tf-woo-product-grid PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.0.1 CVE-2025-59007 Patchstack
10.0 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-49387 Patchstack
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-7384 Wordfence
9.8 Critical Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.1.1 CVE-2025-7697 Wordfence
9.8 Critical Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.2.3 CVE-2025-7696 Wordfence
9.8 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.1 CVE-2025-7340 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Path Traversal Directory Traversal to Arbitrary File Move No login needed ≤ 2.2.1 CVE-2025-7360 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.1 CVE-2025-7341 Wordfence
10.0 Critical Reformer for Elementor Plugin reformer-elementor Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2025-49444 Patchstack
9.8 Critical Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-39588 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-49271 Patchstack
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
9.8 Critical News Element Elementor Blog Magazine Plugin news-element Local File Inclusion Unauthenticated LFI No login needed < 1.0.6 Fixed in 1.0.6 CVE-2024-6459 WPScan
9.9 Critical Zita Elementor Site Library Plugin zita-site-library Remote Code Execution Arbitrary Code Execution ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37420 Patchstack
9.9 Critical Consulting Elementor Widgets Plugin Remote Code Execution ≤ 1.3.0, ≤ 1.2.2 Fixed in 1.3.1 CVE-2024-37091 Patchstack
9.0 Critical Consulting Elementor Widgets Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37089 Patchstack
9.0 Critical CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.1 CVE-2024-4371 Wordfence
9.1 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Path Traversal Unauthenticated Path Traversal to Arbitrary Directory Deletion No login needed ≤ 1.7.15 CVE-2024-5153 Wordfence
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
9.8 Critical WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.1.37 CVE-2024-5147 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only