WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget ≤ 1.4.9 CVE-2025-3106 Wordfence
6.4 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.36 CVE-2024-13650 Wordfence
7.1 High HT Event Plugin ht-event Cross-Site Scripting WordPress Event Manager Plugin for Elementor Plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-24624 Patchstack
7.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.14 Fixed in 6.0.15 CVE-2025-24752 Patchstack
9.8 Critical Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-39588 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.977 Fixed in 1.3.979 CVE-2025-39543 Patchstack
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Request Forgery No login needed ≤ 6.6.2 Fixed in 6.6.3 CVE-2025-39546 Patchstack
4.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Information Disclosure Sensitive Data Exposure ≤ 6.1.9 Fixed in 6.1.10 CVE-2025-39589 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.1.9 Fixed in 6.1.10 CVE-2025-39590 Patchstack
4.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Server-Side Request Forgery ≤ 1.7.1006 Fixed in 1.7.1007 CVE-2025-26990 Patchstack
6.5 Medium RS Elements Elementor Addon Plugin rselements-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.5 CVE-2025-26745 Patchstack
6.4 Medium Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rael_title_tag' ≤ 1.6.9 CVE-2025-2225 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1012 CVE-2025-1456 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1012 CVE-2025-1455 Wordfence
8.1 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-32672 Patchstack
5.3 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Broken Access Control No login needed ≤ 2.1.10 CVE-2025-32260 Patchstack
6.4 Medium Spider Elements Plugin spider-elements Broken Access Control Addons for Elementor plugin <= 1.6.6 - Broken Access Control ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-32216 Patchstack
7.5 High aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32158 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
4.3 Medium WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32269 Patchstack
4.3 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Request Forgery Elementor Addons plugin <= 2.0.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.2 CVE-2025-32264 Patchstack
7.6 High Split Test For Elementor Plugin split-test-for-elementor SQL Injection ≤ 1.8.3 Fixed in 1.8.4 CVE-2025-32204 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.36 CVE-2025-32197 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2025-32196 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-32194 Patchstack
6.5 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32192 Patchstack
6.5 Medium News Element Elementor Blog Magazine Plugin news-element Cross-Site Scripting ≤ 1.0.9 CVE-2025-32191 Patchstack
6.5 Medium Musician's Pack For Elementor Plugin music-pack-for-elementor Cross-Site Scripting ≤ 1.8.7 CVE-2025-32190 Patchstack
6.5 Medium BWD Elementor Addons Plugin bwd-elementor-addons Cross-Site Scripting ≤ 4.4.2 CVE-2025-32189 Patchstack
6.5 Medium Turbo Addons Elementor Plugin turbo-addons-elementor Cross-Site Scripting ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-32186 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.5.0 Fixed in 2.6.0 CVE-2025-32184 Patchstack
6.5 Medium Spider Elements Plugin spider-elements Cross-Site Scripting Addons for Elementor plugin <= 1.6.5 - Cross Site Scripting (XSS) ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-32182 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.10 Fixed in 1.4.11 CVE-2025-32163 Patchstack
7.5 High Sparkle Elementor Kit Plugin sparkle-elementor-kit Local File Inclusion ≤ 2.0.9 CVE-2025-32157 Patchstack
5.9 Medium Split Test For Elementor Plugin split-test-for-elementor Cross-Site Scripting ≤ 1.8.4 CVE-2025-32135 Patchstack
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.142 CVE-2025-1663 Wordfence
6.5 Medium Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting ≤ 2.0.40 CVE-2025-31889 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.9 CVE-2025-31869 Patchstack
6.5 Medium Directorist AddonsKit for Elementor Plugin addonskit-for-elementor Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-31857 Patchstack
6.5 Medium PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Cross-Site Scripting ≤ 2.1.0 Fixed in 2.2.0 CVE-2025-31850 Patchstack
6.5 Medium WPoperation Elementor Addons Plugin wpop-elementor-addons Cross-Site Scripting ≤ 1.1.9 CVE-2025-31823 Patchstack
6.5 Medium WPSHARE247 Elementor Addons Plugin wpshare247-elementor-addons Cross-Site Scripting ≤ 2.5 CVE-2025-31813 Patchstack
5.4 Medium ElementsCSS Addons for Elementor Plugin css-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.8.9 CVE-2025-31796 Patchstack
6.5 Medium Team Members for Elementor Page Builder Plugin team-members-for-elementor Cross-Site Scripting ≤ 1.0.4 CVE-2025-31771 Patchstack
6.5 Medium HMH Footer Builder For Elementor Plugin hmh-footer-builder-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2025-31749 Patchstack
6.4 Medium PowerPack Elementor Addons (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 CVE-2025-1512 Wordfence
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
4.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control ≤ 24.12.58 Fixed in 24.12.59 CVE-2025-30926 Patchstack
9.9 Critical RTMKit Plugin rometheme-for-elementor Remote Code Execution Arbitrary Plugin Installation/Activation to RCE ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-30911 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-31567 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only