WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.22 Fixed in 2.0.23 CVE-2026-105064 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.109 Fixed in 4.11.110 CVE-2026-103084 Patchstack
6.3 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Subscriber+ SQLi via get_addon_output_data 1.5.142 – < 2.0.21 Fixed in 2.0.21 CVE-2026-92923 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQLi via 'ucs' Parameter No login needed 1.5.139 – < 2.0.21 Fixed in 2.0.21 CVE-2026-85568 WPScan
6.6 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated Arbitrary File Write via Path Traversal < 2.0.21 Fixed in 2.0.21 CVE-2026-85015 WPScan
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget ≤ 1.3.2 CVE-2025-12828 Wordfence
5.4 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 3.2.19 CVE-2026-100180 Wordfence
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Icon Library Parameter < 2.0.21 Fixed in 2.0.21 CVE-2026-85016 WPScan
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.8.4 Fixed in 6.8.5 CVE-2026-102394 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103063 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103064 Patchstack
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103341 Patchstack
6.5 Medium Cool Formkit Lite Plugin extensions-for-elementor-form Cross-Site Scripting ≤ 2.7.8 Fixed in 2.7.9 CVE-2026-97301 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.86 Fixed in 51.1.87 CVE-2026-97298 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.85 Fixed in 51.1.86 CVE-2026-96835 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.5.1 Fixed in 6.5.2 CVE-2026-96829 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.23.1 Fixed in 3.50.0 CVE-2026-62080 Patchstack
6.5 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting ≤ 1.11 Fixed in 1.11.1 CVE-2026-62079 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-62078 Patchstack
6.4 Medium HT Mega Addons for Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting ≤ 3.1.1 CVE-2026-11895 Wordfence
4.3 Medium Image Optimizer by Elementor Plugin Information Disclosure Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks < 1.7.7 Fixed in 1.7.7 CVE-2026-90953 WPScan
6.8 Medium Hostinger Reach Plugin hostinger-reach Cross-Site Scripting Contributor+ Stored XSS via formId Elementor Widget Attribute 1.0.6 – < 1.8.3 Fixed in 1.8.3 CVE-2026-87777 WPScan
6.8 Medium EmbedPress Plugin embedpress Cross-Site Scripting Contributor+ Stored XSS via Elementor Widget showTitle Attribute 4.4.9 – < 4.6.7 Fixed in 4.6.7 CVE-2026-85001 WPScan
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-94500 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-94168 Patchstack
6.8 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Contributor+ Stored XSS via Creative Button Widget < 3.50.0 Fixed in 3.50.0 CVE-2026-85006 WPScan
6.4 Medium Gum Addon for Elementor Plugin gum-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting ≤ 1.3.15 CVE-2026-8354 Wordfence
6.5 Medium Wow Elements Addons for Elementor Plugin wow-elements-addons-for-elementor Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting No login needed ≤ 1.11.2 CVE-2026-1641 Wordfence
6.1 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 's' Parameter No login needed ≤ 1.11 CVE-2026-92249 Wordfence
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Template Catalog Import < 51.1.81 Fixed in 51.1.81 CVE-2026-84902 WPScan
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Unauthenticated Popup Deactivation via jltma_popup_disable_expired No login needed 3.0.0 – < 3.1.9 Fixed in 3.1.9 CVE-2026-91015 WPScan
6.1 Medium Royal Elementor Addons Plugin Content Injection Unauthenticated Stored HTML Injection in Form Notification Emails No login needed < 1.7.1067 Fixed in 1.7.1067 CVE-2026-13407 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget < 1.7.9 Fixed in 1.7.9 CVE-2026-84088 WPScan
6.8 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings ≤ 1.5.7 CVE-2026-16593 WPScan
6.4 Medium ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets Plugin shopengine Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter ≤ 4.9.5 CVE-2026-85575 Wordfence
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed ≤ 1.7.1066 CVE-2026-17585 Wordfence
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
5.3 Medium Persian Elementor Plugin Price Manipulation Unauthenticated ZarinPal Payment Callback Authority Bypass No login needed 2.7.10 – < 2.8.2 Fixed in 2.8.2 CVE-2026-86809 WPScan
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.16 CVE-2026-77150 Wordfence
6.8 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Table Widget 3.7.1 – < 3.10.4 Fixed in 3.10.4 CVE-2026-83541 WPScan
6.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting ≤ 3.1.11 CVE-2026-13709 Wordfence
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed ≤ 2.0.17 CVE-2026-75586 Wordfence
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Magazine Grid Widget < 51.1.77 Fixed in 51.1.77 CVE-2026-84896 WPScan
5.3 Medium Xpro Elementor Addons Plugin Information Disclosure Unauthenticated Draft/Private Product Disclosure via Quick View No login needed < 1.7.8 Fixed in 1.7.8 CVE-2026-84146 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only