WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 50 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103355 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103344 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103342 Patchstack
6.3 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Subscriber+ SQLi via get_addon_output_data 1.5.142 – < 2.0.21 Fixed in 2.0.21 CVE-2026-92923 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQLi via 'ucs' Parameter No login needed 1.5.139 – < 2.0.21 Fixed in 2.0.21 CVE-2026-85568 WPScan
6.6 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated Arbitrary File Write via Path Traversal < 2.0.21 Fixed in 2.0.21 CVE-2026-85015 WPScan
5.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data < 2.0.21 Fixed in 2.0.21 CVE-2026-92924 WPScan
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Icon Library Parameter < 2.0.21 Fixed in 2.0.21 CVE-2026-85016 WPScan
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103341 Patchstack
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor PHP Object Injection Subscriber+ PHP Object Injection < 2.0.20 Fixed in 2.0.20 CVE-2026-85017 WPScan
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.16 CVE-2026-18561 Wordfence
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.16 CVE-2026-77150 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed ≤ 2.0.17 CVE-2026-75586 Wordfence
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-85304 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
5.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.15 Fixed in 2.0.16 CVE-2026-28147 Patchstack
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-10081 WPScan
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.12 Fixed in 2.0.13 CVE-2026-57718 Patchstack
9.9 Critical Unlimited Elements for Elementor (Premium) Plugin unlimited-elements-for-elementor-premium Arbitrary File Upload ≤ 2.0.6 CVE-2026-27041 Patchstack
8.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-48837 Patchstack
6.5 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter ≤ 2.0.7 CVE-2026-5486 Wordfence
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal No login needed ≤ 2.0.6 CVE-2026-4659 Wordfence
7.2 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Entry Fields No login needed ≤ 2.0.5 CVE-2026-2724 Wordfence
5.4 Medium Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget ≤ 2.0.1 CVE-2025-14274 Wordfence
7.2 High Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 2.0 CVE-2025-13692 Wordfence
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.148 CVE-2025-8603 Wordfence
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.142 CVE-2025-1663 Wordfence
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget ≤ 1.5.140 CVE-2024-13155 Wordfence
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.135 CVE-2024-13153 Wordfence
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-49271 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-45454 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'username' ≤ 1.5.112 CVE-2024-6169 Wordfence
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'email' ≤ 1.5.112 CVE-2024-6170 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Time-Based SQL Injection ≤ 1.5.112 CVE-2024-6166 Wordfence
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Other IP Address Spoofing to Antispam Bypass No login needed ≤ 1.5.112 CVE-2024-6171 Wordfence
8.3 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control Multiple Broken Access Control ≤ 1.5.65 Fixed in 1.5.66 CVE-2023-31080 Patchstack
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter ≤ 1.5.109 CVE-2024-5329 Wordfence
4.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 1.5.109 Fixed in 1.5.110 CVE-2024-35674 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated(Contributor+) Remote Code Execution via template import ≤ 1.5.89 CVE-2023-6743 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via data[post_ids][0] ≤ 1.5.107 CVE-2024-4779 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.5.102 CVE-2024-3055 Wordfence
6.1 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.5.102 CVE-2024-3547 Wordfence
7.2 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated (Admin+) Command Injection ≤ 1.5.102 CVE-2024-2662 Wordfence
9.9 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.60 Fixed in 1.5.61 CVE-2023-31090 Patchstack
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link ≤ 1.5.96 CVE-2024-0367 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.93 Fixed in 1.5.94 CVE-2024-29792 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only