WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 701–750 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget ≤ 2.1.8 CVE-2024-13644 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 2.8.1 CVE-2024-12599 Wordfence
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.7 CVE-2024-13699 Wordfence
4.3 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 1.6.2 CVE-2024-12046 Wordfence
6.4 Medium HT Mega Plugin ht-mega-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css ≤ 2.7.6 CVE-2024-12597 Wordfence
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Arbitrary File Read No login needed ≤ 1.7.5 Fixed in 2.0.1 CVE-2025-24569 Patchstack
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.12 CVE-2024-13547 Wordfence
4.3 Medium HT Event – WordPress Event Manager Plugin for Elementor Plugin Information Disclosure WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor ≤ 1.4.7 CVE-2024-13216 Wordfence
5.4 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.6.2 CVE-2024-10867 Wordfence
4.3 Medium Elementor Website Builder Pro – More than Just a Page Builder Plugin Information Disclosure More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 3.25.10 CVE-2024-8494 Wordfence
7.2 High Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Remote Code Execution Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.0 - Authenticated (Administrator+) Remote Code Execution ≤ 1.6.0 CVE-2024-11600 Wordfence
4.3 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Broken Access Control Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing Authorization to Icon Font Deletion ≤ 1.5.9 CVE-2024-11583 Wordfence
6.4 Medium Stratum – Elementor Widgets Plugin Cross-Site Scripting Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerability via Image Hotspot Widget ≤ 1.4.7 CVE-2024-13642 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-24743 Patchstack
7.1 High WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-dynamics-crm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24708 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-24584 Patchstack
6.4 Medium Power Ups for Elementor Plugin power-ups-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-13548 Wordfence
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-24729 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-24725 Patchstack
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-24618 Patchstack
6.5 Medium All Embed – Elementor Addons Plugin all-embed-addons-for-elementor Cross-Site Scripting Elementor Addons plugin <= 1.1.3 - Cross Site Scripting (XSS) ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-24595 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-24578 Patchstack
4.3 Medium RomethemeKit For Elementor Plugin rometheme-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 1.5.2 CVE-2024-10324 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
6.4 Medium Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.4 CVE-2024-13354 Wordfence
4.3 Medium Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates Plugin sastra-essential-addons-for-elementor Broken Access Control Free Elementor Addons, Widgets and Templates <= 1.0.14 - Missing Authorization to Spexo Theme Install ≤ 1.0.14 CVE-2024-13335 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.16.5 CVE-2024-12043 Wordfence
6.5 Medium Elementor AI Addons Plugin ai-addons-for-elementor Cross-Site Scripting ≤ 2.2.1 CVE-2025-22758 Patchstack
7.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Local File Inclusion ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-22786 Patchstack
4.3 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup ≤ 1.13.10 CVE-2024-13215 Wordfence
4.3 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.4.32 CVE-2024-10775 Wordfence
6.1 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.7.1006 CVE-2025-0393 Wordfence
4.3 Medium Unlimited Theme Addon For Elementor and WooCommerce Plugin unlimited-theme-addons Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.2 CVE-2024-12116 Wordfence
4.3 Medium RRAddons for Elementor Plugin rrdevs-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.1.0 CVE-2024-11915 Wordfence
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-22806 Patchstack
6.5 Medium MT Addons for Elementor Plugin mt-addons-for-elementor Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-22811 Patchstack
6.5 Medium News Ticker Widget for Elementor Plugin news-ticker-widget-for-elementor Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-22812 Patchstack
6.5 Medium S3Player – WooCommerce & Elementor Integration Plugin drm-protected-video-streaming Cross-Site Scripting ≤ 4.2.1 CVE-2025-22818 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.135 CVE-2024-13153 Wordfence
6.4 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.1.7 CVE-2024-12328 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.15.1 CVE-2024-12852 Wordfence
4.3 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Information Disclosure FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication ≤ 1.4.6.2 CVE-2024-12584 Wordfence
6.4 Medium Element Pack Lite - Addons for Elementor Plugin Cross-Site Scripting Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.10.14 CVE-2024-12851 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.4 CVE-2024-12205 Wordfence
6.5 Medium Alpha Price Table For Elementor Plugin alpha-price-table-for-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2025-22500 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only