WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 501–550 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-7384 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox ≤ 2.0.9.0 CVE-2025-8874 Wordfence
4.9 Medium Elementor Plugin elementor Path Traversal Authenticated (Administrator+) Arbitrary File Read via Image Import ≤ 3.30.2 CVE-2025-8081 Wordfence
6.4 Medium RT Easy Builder Plugin rt-easy-builder-advanced-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3 CVE-2025-8462 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown ≤ 2.7.9.4 CVE-2025-7498 Wordfence
5.4 Medium Element Pack Elementor Addons and Templates Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content ≤ 8.1.5 CVE-2025-8100 Wordfence
4.3 Medium Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Plugin header-footer-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 2.4.6 CVE-2025-8488 Wordfence
6.4 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter Widget ≤ 1.6.4 CVE-2025-8212 Wordfence
6.4 Medium Qi Addons for Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via TypeOut Text Widget ≤ 1.9.2 CVE-2025-8146 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `Sina Posts`, `Sina Blog Post` and `Sina Table` Widgets ≤ 3.7.0 CVE-2025-6228 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.10 CVE-2025-7646 Wordfence
6.4 Medium Stratum – Elementor Widgets Plugin stratum Cross-Site Scripting Elementor Widgets <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Google Maps and Image Hotspot Widgets ≤ 1.6.0 CVE-2025-7845 Wordfence
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Broken Access Control Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions ≤ 2.9.1 CVE-2025-8068 Wordfence
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Information Disclosure Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure ≤ 2.9.1 CVE-2025-8401 Wordfence
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Path Traversal Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions ≤ 2.9.1 CVE-2025-8151 Wordfence
6.4 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes ≤ 1.3.8 CVE-2025-8196 Wordfence
6.4 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.1.4 CVE-2025-8216 Wordfence
6.4 Medium Elementor Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Text Path Widget ≤ 3.30.2 CVE-2025-4566 Wordfence
6.4 Medium Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.29.0 CVE-2025-3075 Wordfence
6.4 Medium ElementsKit Elementor Addons and Templates Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget ≤ 3.5.2 CVE-2025-3614 Wordfence
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
9.8 Critical Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.1.1 CVE-2025-7697 Wordfence
9.8 Critical Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive PHP Object Injection Unauthenticated PHP Object Injection via verify_field_val Function No login needed ≤ 1.2.3 CVE-2025-7696 Wordfence
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-48295 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54050 Patchstack
5.4 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-54037 Patchstack
6.5 Medium Theme Builder For Elementor Plugin theme-builder-for-elementor Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-54033 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.19 Fixed in 1.3.19.1 CVE-2025-53989 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53982 Patchstack
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.8.2 CVE-2025-5284 Wordfence
9.8 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.1 CVE-2025-7340 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Path Traversal Directory Traversal to Arbitrary File Move No login needed ≤ 2.2.1 CVE-2025-7360 Wordfence
9.1 Critical HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. Plugin ht-contactform Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.2.1 CVE-2025-7341 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets ≤ 6.1.19 CVE-2025-6244 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.10.69 CVE-2024-11937 Wordfence
6.4 Medium Portfolio for Elementor & Image Gallery | PowerFolio Plugin portfolio-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.2.0 CVE-2025-7046 Wordfence
6.4 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute 8.0.0 CVE-2025-5944 Wordfence
6.4 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit <= 2.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via button+modal Widget ≤ 2.5.4 CVE-2025-2330 Wordfence
6.4 Medium Magic Buttons for Elementor Plugin magic-buttons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode ≤ 1.0 CVE-2025-6686 Wordfence
6.4 Medium Magic Buttons for Elementor Plugin magic-buttons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode ≤ 1.0 CVE-2025-6687 Wordfence
5.4 Medium The Plus Addons for Elementor Pro Plugin theplus_elementor_addon Broken Access Control Pro Plugin < 6.3.7 - Broken Access Control < 6.3.7 Fixed in 6.3.7 CVE-2025-46259 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.1 CVE-2025-6252 Wordfence
7.5 High Devnex Addons For Elementor Plugin devnex-addons-for-elementor Local File Inclusion ≤ 1.0.9 CVE-2025-53339 Patchstack
6.5 Medium HT Slider For Elementor Plugin ht-slider-for-elementor Cross-Site Scripting ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-53199 Patchstack
6.4 Medium The Pack Elementor addon Plugin the-pack-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.4 CVE-2025-6550 Wordfence
6.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets ≤ 1.7.1028 CVE-2025-5338 Wordfence
4.3 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function ≤ 1.6.0 CVE-2025-3863 Wordfence
6.5 Medium Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Scripting ≤ 1.2.8 CVE-2025-50038 Patchstack
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
10.0 Critical Reformer for Elementor Plugin reformer-elementor Arbitrary File Upload No login needed ≤ 1.0.5 CVE-2025-49444 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only