WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–50 of 190 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting No login needed |
≤ 2.0.20 Fixed in 2.0.21 |
CVE-2026-103344 |
Patchstack | |
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting No login needed |
≤ 2.0.20 Fixed in 2.0.21 |
CVE-2026-103342 |
Patchstack | |
| 7.5 High | WPCafe | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting |
≤ 3.0.18 |
CVE-2026-75028 |
Wordfence | |
| 8.5 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection |
≤ 2.0.20 Fixed in 2.0.21 |
CVE-2026-103338 |
Patchstack | |
| 7.2 High | LA-Studio Element Kit for Elementor | Server-Side Request Forgery No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-103082 |
Patchstack | |
| 7.2 High | Repeater Fields for Elementor Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Field Value No login needed |
≤ 2.2.7 |
CVE-2026-94573 |
Wordfence | |
| 8.8 High | Elementor Website Builder | Cross-Site Request Forgery No login needed |
≤ 4.3.1 Fixed in 4.3.2 |
CVE-2026-62062 |
Patchstack | |
| 7.2 High | MasterStudy LMS 3.5.29 | Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget |
3.5.29 – < 3.7.50 Fixed in 3.7.50 |
CVE-2026-88843 |
WPScan | |
| 8.5 High | Live Copy Paste for Elementor | SQL Injection |
≤ 1.5.10 Fixed in 1.5.11 |
CVE-2026-93527 |
Patchstack | |
| 7.5 High | Unlimited Elements For Elementor | PHP Object Injection Subscriber+ PHP Object Injection |
< 2.0.20 Fixed in 2.0.20 |
CVE-2026-85017 |
WPScan | |
| 7.2 High | Jeg Kit for Elementor | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed |
≤ 3.2.16 |
CVE-2026-18405 |
Wordfence | |
| 8.1 High | Master Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter |
≤ 3.2.2 |
CVE-2026-85410 |
Wordfence | |
| 7.2 High | Complianz GDPR/CCPA Cookie Consent Banner | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed |
≤ 7.5.4 |
CVE-2026-83561 |
Wordfence | |
| 7.6 High | SKT Addons for Elementor | SQL Injection |
≤ 4.0 Fixed in 4.1 |
CVE-2026-66626 |
Patchstack | |
| 7.1 High | Master Addons for Elementor | Broken Access Control |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2026-62089 |
Patchstack | |
| 7.6 High | Sky Addons for Elementor | SQL Injection |
≤ 3.8.4 Fixed in 3.8.5 |
CVE-2026-62109 |
Patchstack | |
| 7.5 High | Unlimited Elements For Elementor | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.0.16 |
CVE-2026-18561 |
Wordfence | |
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting No login needed |
≤ 2.0.17 Fixed in 2.0.18 |
CVE-2026-84820 |
Patchstack | |
| 7.1 High | RTMKit | Cross-Site Scripting No login needed |
≤ 2.1.5 Fixed in 2.1.6 |
CVE-2026-84763 |
Patchstack | |
| 8.8 High | RTMKit | PHP Object Injection |
≤ 2.1.5 Fixed in 2.1.6 |
CVE-2026-84752 |
Patchstack | |
| 7.2 High | Master Addons for Elementor | Broken Access Control Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction |
≤ 3.1.9 |
CVE-2026-75921 |
Wordfence | |
| 7.2 High | ShopEngine Elementor WooCommerce Builder Addon | Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes |
≤ 4.9.4 |
CVE-2026-75971 |
Wordfence | |
| 8.6 High | ShopBuilder Pro – Elementor WooCommerce Builder Addons | Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed |
≤ 2.2.0 |
CVE-2026-32477 |
Patchstack | |
| 7.2 High | Animation Addons for Elementor | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
< 2.7.2 Fixed in 2.7.2 |
CVE-2026-17565 |
WPScan | |
| 7.1 High | Recipe Card Blocks for Gutenberg & Elementor | Cross-Site Scripting No login needed |
≤ 3.4.18 Fixed in 3.4.19 |
CVE-2026-73361 |
Patchstack | |
| 7.2 High | PDF Smart Viewer for Elementor | Server-Side Request Forgery No login needed |
≤ 1.0.4 |
CVE-2026-32473 |
Patchstack | |
| 8.8 High | Royal Addons for Elementor | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting |
≤ 1.7.1064 |
CVE-2026-17123 |
Wordfence | |
| 8.1 High | Essential Addons for Elementor | Privilege Escalation Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment No login needed |
5.8.6 – < 6.7.2 Fixed in 6.7.2 |
CVE-2026-18039 |
WPScan | |
| 7.2 High | Jeg Kit for Elementor | PHP Object Injection |
≤ 3.2.10 Fixed in 3.2.11 |
CVE-2026-65549 |
Patchstack | |
| 8.8 High | DynamicKit for Elementor | Privilege Escalation Unauthenticated Account Takeover via Password Reset Link Host Injection No login needed |
< 1.0.3 Fixed in 1.0.3 |
CVE-2026-14596 |
WPScan | |
| 7.1 High | Database for Contact Form 7, WPforms, Elementor forms | Cross-Site Scripting Reflected XSS via form_id No login needed |
< 1.5.3 Fixed in 1.5.3 |
CVE-2026-14870 |
WPScan | |
| 7.1 High | LA-Studio Element Kit for Elementor | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-65488 |
Patchstack | |
| 8.8 High | CRT Addons for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Contact Form No login needed |
< 1.6.7 Fixed in 1.6.7 |
CVE-2026-11767 |
WPScan | |
| 8.8 High | Unlimited Elements for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed |
< 2.0.11 Fixed in 2.0.11 |
CVE-2026-10081 |
WPScan | |
| 7.5 High | TheGem Theme Elements (for Elementor) | Local File Inclusion |
< 5.12.1.1 Fixed in 5.12.1.1 |
CVE-2026-57804 |
Patchstack | |
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting No login needed |
≤ 2.0.12 Fixed in 2.0.13 |
CVE-2026-57718 |
Patchstack | |
| 7.1 High | ElementInvader Addons for Elementor | Cross-Site Scripting No login needed |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2026-57376 |
Patchstack | |
| 8.8 High | Essential Addons for Elementor | Privilege Escalation Authenticated (Contributor+) Account Takeover via Email Header Injection |
≤ 6.6.10 |
CVE-2026-15155 |
Wordfence | |
| 7.5 High | LA-Studio Element Kit for Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting |
≤ 1.6.1 |
CVE-2026-15338 |
Wordfence | |
| 8.1 High | Database for Contact Form 7, WPforms, Elementor forms | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed |
≤ 1.5.1 |
CVE-2026-9843 |
Wordfence | |
| 7.1 High | Royal Elementor Addons Pro | Cross-Site Scripting No login needed |
< 1.7.1041 Fixed in 1.7.1041 |
CVE-2026-40720 |
Patchstack | |
| 8.8 High | PowerPack Pro for Elementor | Authentication Bypass Broken Authentication No login needed |
< v2.13.0 Fixed in 2.13.0 |
CVE-2026-42629 |
Patchstack | |
| 7.1 High | WPZOOM Addons for Elementor | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.4 Fixed in 1.3.5 |
CVE-2026-39597 |
Patchstack | |
| 7.1 High | Product Filter Widget for Elementor | Cross-Site Scripting No login needed |
≤ 1.0.6 |
CVE-2026-45437 |
Patchstack | |
| 8.5 High | Unlimited Elements For Elementor | SQL Injection |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2026-48837 |
Patchstack | |
| 8.8 High | Easy Elements for Elementor – Addons & Website Templates | Privilege Escalation Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter |
≤ 1.4.5 |
CVE-2026-9018 |
Wordfence | |
| 8.8 High | RTMKit Addons for Elementor | Local File Inclusion Authenticated (Author+) Local File Inclusion via 'path' |
≤ 2.0.2 |
CVE-2026-3425 |
Wordfence | |
| 8.5 High | Xpro Elementor Addons | SQL Injection |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-45214 |
Patchstack | |
| 7.2 High | Royal Addons for Elementor | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta No login needed |
≤ 1.7.1056 |
CVE-2026-4803 |
Wordfence | |
| 7.2 High | Royal Addons for Elementor | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter No login needed |
≤ 1.7.1057 |
CVE-2026-6229 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.