WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–25 of 25 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Unauthenticated Popup Deactivation via jltma_popup_disable_expired No login needed 3.0.0 – < 3.1.9 Fixed in 3.1.9 CVE-2026-91015 WPScan
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) ≤ 3.1.0 CVE-2026-9281 Wordfence
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2026-32462 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2024-52387 Patchstack
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' ≤ 2.1.1 CVE-2026-2486 Wordfence
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2025-63053 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control No login needed ≤ 2.0.5.3 Fixed in 2.0.5.4.1 CVE-2023-40679 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2025-63055 Patchstack
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox ≤ 2.0.9.0 CVE-2025-8874 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.8.2 CVE-2025-5284 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 2.0.7.1 CVE-2025-0433 Wordfence
6.4 Medium Master Addons Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.0.7.2 CVE-2024-9618 Wordfence
6.4 Medium Master Addons -- Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip Module ≤ 2.0.6.7 CVE-2024-9502 Wordfence
5.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element ≤ 2.0.6.4 CVE-2024-6282 Wordfence
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on API No login needed ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-35660 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.9 Fixed in 2.0.6.0 CVE-2024-35688 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.6.0 Fixed in 2.0.6.1 CVE-2024-35702 Patchstack
6.5 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification No login needed ≤ 2.0.6.1 CVE-2024-5382 Wordfence
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-3134 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-4580 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting ≤ 2.0.5.9 CVE-2024-4265 Wordfence
4.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on Duplicate Post ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-33595 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-29911 Patchstack
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 2.0.5.6 CVE-2024-2139 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only