WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 601–650 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements Plugin ai-addons-for-elementor Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure ≤ 2.2.1 CVE-2024-12140 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-56241 Patchstack
5.4 Medium Dragfy Addons for Elementor Plugin dragfy-addons-for-elementor Broken Access Control Broken Access Control + CSRF ≤ 1.0.2 CVE-2023-47661 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.987 Fixed in 1.7.1 CVE-2024-56062 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
6.5 Medium WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-56221 Patchstack
4.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56227 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget ≤ 1.6.46 CVE-2024-11230 Wordfence
4.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Broken Access Control Missing Authorization ≤ 5.10.12 CVE-2024-11852 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings ≤ 3.25.9 CVE-2024-10453 Wordfence
4.3 Medium Full Screen Menu for Elementor Plugin full-screen-menu-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.7 CVE-2024-10797 Wordfence
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
4.3 Medium Events Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.2.3 CVE-2024-12061 Wordfence
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.4.8 CVE-2024-10356 Wordfence
6.5 Medium Advanced Data Table For Elementor Plugin advanced-data-table-for-elementor Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2024-54443 Patchstack
4.3 Medium Shortcodes for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.4 CVE-2024-10690 Wordfence
6.5 Medium Hello Event Widgets For Elementor Plugin hello-event-widgets-for-elementor Cross-Site Scripting ≤ 1.0.2 Fixed in 1.1.0 CVE-2024-54338 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54316 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-54315 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.2 CVE-2024-54314 Patchstack
4.3 Medium News Ticker for Elementor Plugin news-ticker-for-elementor Broken Access Control ≤ 2.1.3 CVE-2024-54278 Patchstack
5.3 Medium Booster Elementor Addons Plugin booster-for-elementor Broken Access Control No login needed ≤ 1.4.9 CVE-2023-38480 Patchstack
5.4 Medium Dynamic Visibility for Elementor Plugin dynamic-visibility-for-elementor Broken Access Control ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-35046 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.126 CVE-2024-10784 Wordfence
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control Missing Authorization to Arbitrary Options Read ≤ 1.3.1 CVE-2024-12059 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-53816 Patchstack
6.5 Medium ABCBiz Addons and Templates for Elementor Plugin abcbiz-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-54247 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.6.5 Fixed in 1.4.6.6 CVE-2024-54253 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.7 Fixed in 6.4.8 CVE-2024-54224 Patchstack
6.5 Medium Wot Elementor Widgets Plugin wot-elementor-widgets Cross-Site Scripting ≤ 1.0.1 CVE-2024-54228 Patchstack
6.5 Medium Unlock Addons for Elementor Plugin unlock-addons-for-elementor Cross-Site Scripting ≤ 2.2.4 CVE-2024-54230 Patchstack
6.5 Medium RRAddons for Elementor Plugin rrdevs-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2024-54232 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2024-54260 Patchstack
5.4 Medium Rife Elementor Extensions & Templates Plugin rife-elementor-extensions Broken Access Control ≤ 1.1.10 Fixed in 1.2.0 CVE-2023-27454 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2023-47826 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Broken Access Control No login needed ≤ 2.1.10 Fixed in 2.2 CVE-2023-48750 Patchstack
5.4 Medium Elementor Timeline Widget Plugin 3r-elementor-timeline-widget Broken Access Control Notice Dismissal ≤ 2.2 Fixed in 2.3 CVE-2023-49755 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2023-50884 Patchstack
5.3 Medium Metform Plugin metform Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2023-50903 Patchstack
6.1 Medium Smoove connector for Elementor forms Plugin smoove-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.0 CVE-2024-11367 Wordfence
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-53796 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.14 Fixed in 6.0.1 CVE-2024-53823 Patchstack
5.9 Medium Borderless Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin <= 1.5.8 - Cross Site Scripting (XSS) ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54211 Patchstack
6.5 Medium Advanced Element Bucket Addons for Elementor Plugin cs-element-bucket Cross-Site Scripting ≤ 1.0.2 CVE-2024-54210 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54212 Patchstack
4.3 Medium PowerPack Elementor Addons (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.8.1 CVE-2024-10692 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only