WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Digital Marketing and Agency Templates Addons for Elementor Plugin digital-marketing-agency-templates-for-elementor Cross-Site Request Forgery Cross-Site Request Forgery to Import No login needed ≤ 1.1.1 CVE-2025-5938 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 4.11.8 CVE-2025-4774 Wordfence
6.4 Medium Elementor Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.29.0 CVE-2025-3076 Wordfence
7.1 High Universal Video Player Plugin elementor_widget_universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-31057 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 6.1.12 CVE-2024-9994 Wordfence
4.3 Medium Layouts for Elementor Plugin layouts-for-elementor Cross-Site Request Forgery No login needed ≤ 1.11 CVE-2025-30948 Patchstack
7.6 High Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting ≤ 3.6.1 Fixed in 3.7.0 CVE-2025-49262 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-49235 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.2.7 Fixed in 6.2.8 CVE-2025-49076 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-49074 Patchstack
6.4 Medium Music Player for Elementor Plugin music-player-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via album_buy_url Parameter ≤ 2.4.6 CVE-2025-5340 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1020 CVE-2025-3813 Wordfence
6.4 Medium Borderless – Elementor Addons and Templates Plugin borderless Cross-Site Scripting Elementor Addons and Templates <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1 CVE-2025-5290 Wordfence
6.4 Medium Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder Plugin Cross-Site Scripting Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.11.2 CVE-2025-5292 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets ≤ 1.5.2 CVE-2025-4944 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter ≤ 1.5.2 CVE-2025-4943 Wordfence
5.3 Medium Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.4.4 CVE-2025-4659 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget ≤ 2.7.9.1 CVE-2025-4783 Wordfence
7.1 High WP Post Modules for Elementor Plugin wp-post-modules-el Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-31636 Patchstack
8.6 High Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2025-47492 Patchstack
7.5 High JetElements For Elementor Plugin jet-elements Broken Access Control No login needed ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39447 Patchstack
7.5 High JetBlocks For Elementor Plugin jet-blocks Broken Access Control No login needed ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-39451 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39448 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-48288 Patchstack
5.9 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.7.9 Fixed in 2.7.9.1 CVE-2025-48244 Patchstack
6.5 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Cross-Site Scripting Lite plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48232 Patchstack
6.5 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-48132 Patchstack
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting ≤ 2.0.2 CVE-2025-48131 Patchstack
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets ≤ 2.6.12 CVE-2025-2944 Wordfence
4.7 Medium Integrations of Zoho CRM with Elementor form Plugin integrations-of-zoho-crm-with-elementor-form Open Redirect No login needed ≤ 1.0.8 CVE-2025-47644 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-47542 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
5.3 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control No login needed ≤ 3.1.9 Fixed in 3.2.0 CVE-2025-47486 Patchstack
5.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47480 Patchstack
6.5 Medium Cost Calculator for Elementor Plugin cost-calculator-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-47476 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.7.1017 Fixed in 1.7.1018 CVE-2025-39361 Patchstack
5.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1017 CVE-2024-12120 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.10.29 CVE-2025-1458 Wordfence
8.8 High Xpro Elementor Addons - Pro Plugin Remote Code Execution Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution ≤ 1.4.9 CVE-2024-13808 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.6 CVE-2025-46472 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 3.0.1 Fixed in 3.0.3 CVE-2025-46260 Patchstack
6.4 Medium UiCore Elements – Free Elementor widgets and templates Plugin uicore-elements Cross-Site Scripting Free Elementor widgets and templates <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.0.16 CVE-2025-1054 Wordfence
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-46249 Patchstack
6.5 Medium Post in page for Elementor Plugin post-in-page-for-elementor Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-46225 Patchstack
7.5 High CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon Plugin Path Traversal HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon <= 2.4 - Unauthenticated Arbitrary File Read No login needed ≤ 2.4 CVE-2025-3103 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.5 CVE-2025-3275 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.28 CVE-2025-1457 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only