WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-51938 Patchstack
6.5 Medium Drozd – Addons for Elementor Plugin drozd-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-52425 Patchstack
4.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Cross-Site Request Forgery All In One Form Integration including DB for Elementor <= 2.9.9.9 - Cross-Site Request Forgery No login needed ≤ 2.9.9.9 CVE-2024-6628 Wordfence
5.7 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 6.0.9 CVE-2024-8978 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.7 CVE-2024-8961 Wordfence
4.3 Medium Music Player for Elementor – Audio Player & Podcast Player Plugin music-player-for-elementor Broken Access Control Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Template Import ≤ 2.4.1 CVE-2024-10582 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation ≤ 2.1.5 CVE-2024-10897 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget ≤ 1.7.1001 CVE-2024-9682 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.7.1001 CVE-2024-9668 Wordfence
6.4 Medium Royal Elementor Addons and Template Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget ≤ 1.7.1001 CVE-2024-9059 Wordfence
4.3 Medium Boostify Header Footer Builder for Elementor Plugin boostify-header-footer-builder Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.3.6 CVE-2024-10794 Wordfence
6.1 Medium Razorpay Payment Button for Elementor Plugin razorpay-payment-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-10850 Wordfence
4.3 Medium BuddyPress Builder for Elementor – BuddyBuilder Plugin stax-buddy-builder Information Disclosure BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.7.4 CVE-2024-10778 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.18 CVE-2024-10323 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison ≤ 3.12.5 CVE-2024-10538 Wordfence
6.5 Medium Web Stories Widgets For Elementor Plugin shortcodes-for-amp-web-stories-and-elementor-widget Cross-Site Scripting ≤ 1.1 Fixed in 1.1.1 CVE-2024-52354 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-52356 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
6.5 Medium MasterBip para Elementor Plugin masterbip-for-elementor Cross-Site Scripting ≤ 1.6.3 CVE-2024-51571 Patchstack
6.5 Medium Extender All In One For Elementor Plugin extender-all-in-one-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2024-51575 Patchstack
6.5 Medium Clever Addons for Elementor Plugin cafe-lite Cross-Site Scripting ≤ 2.2.1 CVE-2024-51580 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-51581 Patchstack
6.5 Medium Marquee Elementor with Posts Plugin marquee-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2024-51584 Patchstack
6.5 Medium Sales Page Addon – Elementor & Beaver Builder Plugin sales-page-addon Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.4.5 CVE-2024-51585 Patchstack
6.5 Medium Definitive Addons for Elementor Plugin definitive-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.5.16 CVE-2024-51587 Patchstack
6.5 Medium Super Addons for Elementor Plugin super-addons-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2024-51588 Patchstack
6.5 Medium Hoo Addons for Elementor Plugin hoo-addons-for-elementor Cross-Site Scripting ≤ 1.0.6 CVE-2024-51590 Patchstack
6.5 Medium Slicko Plugin slicko-for-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2024-51591 Patchstack
6.5 Medium ThemeShark Templates & Widgets for Elementor Plugin themeshark-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-51597 Patchstack
6.5 Medium Header Footer Composer for Elementor Plugin header-footer-composer Cross-Site Scripting ≤ 1.0.4 CVE-2024-51629 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-51662 Patchstack
6.5 Medium Sastra Essential Addons for Elementor Plugin sastra-essential-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51674 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-51675 Patchstack
4.3 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 1.2.4 CVE-2024-10352 Wordfence
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51787 Patchstack
4.3 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 3.3 CVE-2024-10693 Wordfence
6.4 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons <= 1.2.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.0 CVE-2024-8960 Wordfence
5.3 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Information Disclosure Elementor Addons <= 1.2.0 - Authenticated (Contributor+) Post Disclosure No login needed ≤ 1.2.0 CVE-2024-10779 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.6.45 CVE-2024-10325 Wordfence
6.4 Medium Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget ≤ 3.15.18 CVE-2024-8442 Wordfence
5.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Broken Access Control All In One Form Integration including DB for Elementor <= 2.9.9.9 - Missing Authorization No login needed ≤ 2.9.9.9 CVE-2024-6626 Wordfence
4.3 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 1.4.6 CVE-2024-10329 Wordfence
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget ≤ 5.10.2 CVE-2024-9867 Wordfence
6.5 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.2 CVE-2024-9657 Wordfence
4.3 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Information Disclosure FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 1.4.6 CVE-2024-10319 Wordfence
6.5 Medium Cresta Addons for Elementor Plugin cresta-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-51680 Patchstack
6.5 Medium HT Builder – WordPress Theme Builder for Elementor Plugin ht-builder Cross-Site Scripting WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-51682 Patchstack
6.5 Medium Custom post type templates for Elementor Plugin custom-post-type-templates-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.1 Fixed in 1.1.12 CVE-2024-51683 Patchstack
5.9 Medium Accordion title for Elementor Plugin accordion-title-for-elementor Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-51685 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only