WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 751–800 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium BWD Elementor Addons Plugin bwd-elementor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 4.3.18 CVE-2024-12532 Wordfence
7.5 High WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Local File Inclusion ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56282 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2024-56285 Patchstack
6.5 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting ≤ 1.2.9 Fixed in 1.2.9.1 CVE-2025-22312 Patchstack
5.9 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2025-22316 Patchstack
6.5 Medium Image Hover Effects for Elementor Plugin image-hover-effects-elementor-addon Cross-Site Scripting ≤ 1.0.2.4 CVE-2025-22323 Patchstack
6.5 Medium ElementsCSS Addons for Elementor Plugin css-for-elementor Cross-Site Scripting ≤ 1.0.8.9 CVE-2025-22321 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.31 Fixed in 2.4.32 CVE-2025-22333 Patchstack
6.4 Medium Master Addons -- Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip Module ≤ 2.0.6.7 CVE-2024-9502 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Sina Image Differ ≤ 3.5.91 CVE-2024-12624 Wordfence
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
4.3 Medium Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements Plugin ai-addons-for-elementor Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure ≤ 2.2.1 CVE-2024-12140 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-56241 Patchstack
5.4 Medium Dragfy Addons for Elementor Plugin dragfy-addons-for-elementor Broken Access Control Broken Access Control + CSRF ≤ 1.0.2 CVE-2023-47661 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.987 Fixed in 1.7.1 CVE-2024-56062 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
6.5 Medium WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-56221 Patchstack
7.1 High Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56226 Patchstack
4.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56227 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
8.8 High WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Plugin wte-elementor-widgets Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion ≤ 1.3.7 CVE-2024-12272 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget ≤ 1.6.46 CVE-2024-11230 Wordfence
4.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Broken Access Control Missing Authorization ≤ 5.10.12 CVE-2024-11852 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings ≤ 3.25.9 CVE-2024-10453 Wordfence
4.3 Medium Full Screen Menu for Elementor Plugin full-screen-menu-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.7 CVE-2024-10797 Wordfence
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
4.3 Medium Events Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.2.3 CVE-2024-12061 Wordfence
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.4.8 CVE-2024-10356 Wordfence
6.5 Medium Advanced Data Table For Elementor Plugin advanced-data-table-for-elementor Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2024-54443 Patchstack
4.3 Medium Shortcodes for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.4 CVE-2024-10690 Wordfence
6.5 Medium Hello Event Widgets For Elementor Plugin hello-event-widgets-for-elementor Cross-Site Scripting ≤ 1.0.2 Fixed in 1.1.0 CVE-2024-54338 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54316 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-54315 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.2 CVE-2024-54314 Patchstack
4.3 Medium News Ticker for Elementor Plugin news-ticker-for-elementor Broken Access Control ≤ 2.1.3 CVE-2024-54278 Patchstack
5.3 Medium Booster Elementor Addons Plugin booster-for-elementor Broken Access Control No login needed ≤ 1.4.9 CVE-2023-38480 Patchstack
5.4 Medium Dynamic Visibility for Elementor Plugin dynamic-visibility-for-elementor Broken Access Control ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-35046 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.126 CVE-2024-10784 Wordfence
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control Missing Authorization to Arbitrary Options Read ≤ 1.3.1 CVE-2024-12059 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-53816 Patchstack
6.5 Medium ABCBiz Addons and Templates for Elementor Plugin abcbiz-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-54247 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.6.5 Fixed in 1.4.6.6 CVE-2024-54253 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.7 Fixed in 6.4.8 CVE-2024-54224 Patchstack
6.5 Medium Wot Elementor Widgets Plugin wot-elementor-widgets Cross-Site Scripting ≤ 1.0.1 CVE-2024-54228 Patchstack
6.5 Medium Unlock Addons for Elementor Plugin unlock-addons-for-elementor Cross-Site Scripting ≤ 2.2.4 CVE-2024-54230 Patchstack
6.5 Medium RRAddons for Elementor Plugin rrdevs-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2024-54232 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2024-54260 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only