WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 801–850 of 1,616 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Rife Elementor Extensions & Templates | Broken Access Control |
≤ 1.1.10 Fixed in 1.2.0 |
CVE-2023-27454 |
Patchstack | |
| 6.5 Medium | Restaurant & Cafe Addon for Elementor | Broken Access Control No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2023-47826 |
Patchstack | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Broken Access Control No login needed |
≤ 2.1.10 Fixed in 2.2 |
CVE-2023-48750 |
Patchstack | |
| 5.4 Medium | Elementor Timeline Widget | Broken Access Control Notice Dismissal |
≤ 2.2 Fixed in 2.3 |
CVE-2023-49755 |
Patchstack | |
| 6.5 Medium | LA-Studio Element Kit for Elementor | Broken Access Control No login needed |
≤ 1.1.5 Fixed in 1.1.6 |
CVE-2023-50884 |
Patchstack | |
| 5.3 Medium | Metform | Broken Access Control No login needed |
≤ 3.4.0 Fixed in 3.4.1 |
CVE-2023-50903 |
Patchstack | |
| 6.1 Medium | Smoove connector for Elementor forms | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.1.0 |
CVE-2024-11367 |
Wordfence | |
| 6.5 Medium | themesflat-addons-for-elementor | Cross-Site Scripting |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2024-53796 |
Patchstack | |
| 6.5 Medium | The Plus Addons for Elementor Page Builder Lite | Cross-Site Scripting |
≤ 5.6.14 Fixed in 6.0.1 |
CVE-2024-53823 |
Patchstack | |
| 5.9 Medium | Borderless | Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin <= 1.5.8 - Cross Site Scripting (XSS) |
≤ 1.5.8 Fixed in 1.5.9 |
CVE-2024-54211 |
Patchstack | |
| 6.5 Medium | Advanced Element Bucket Addons for Elementor | Cross-Site Scripting |
≤ 1.0.2 |
CVE-2024-54210 |
Patchstack | |
| 6.5 Medium | Magical Addons For Elementor | Cross-Site Scripting |
≤ 1.3.6 Fixed in 1.3.7 |
CVE-2024-54212 |
Patchstack | |
| 4.3 Medium | PowerPack Elementor Addons (Free Widgets, Extensions and Templates) | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 2.8.1 |
CVE-2024-10692 |
Wordfence | |
| 4.3 Medium | XLTab – Accordions and Tabs for Elementor Page Builder | Information Disclosure Accordions and Tabs for Elementor Page Builder <= 1.4 - Authenticated (Contributor+) Post Disclosure |
≤ 1.4 |
CVE-2024-10689 |
Wordfence | |
| 4.3 Medium | Gold Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) License Activation/Deactivation |
≤ 1.3.2 |
CVE-2024-12110 |
Wordfence | |
| 4.3 Medium | AnyWhere Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.2.11 |
CVE-2024-10777 |
Wordfence | |
| 6.4 Medium | WPBITS Addons For Elementor Page Builder | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.5.2 |
CVE-2024-8962 |
Wordfence | |
| 4.3 Medium | LA-Studio Element Kit for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.4.4 |
CVE-2024-10787 |
Wordfence | |
| 4.3 Medium | Eleblog – Elementor Blog And Magazine Addons | Broken Access Control Elementor Blog And Magazine Addons <= 1.8 - Missing Authorization to Authenticated (Subscriber+) Deactivation Submission |
≤ 1.8 |
CVE-2024-10663 |
Wordfence | |
| 4.3 Medium | Charity Addon for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.3.3 |
CVE-2024-12062 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget |
≤ 5.10.5 |
CVE-2024-9058 |
Wordfence | |
| 6.4 Medium | CMSMasters Elementor Addon | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 1.14.7 |
CVE-2024-9694 |
Wordfence | |
| 6.5 Medium | Elementor Portfolio Builder | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2024-52486 |
Patchstack | |
| 6.5 Medium | Generic Elements | Cross-Site Scripting |
≤ 1.2.5 Fixed in 1.2.6 |
CVE-2024-53709 |
Patchstack | |
| 6.5 Medium | Countdown Timer for Elementor | Cross-Site Scripting |
≤ 1.3.6 Fixed in 1.3.7 |
CVE-2024-53743 |
Patchstack | |
| 6.5 Medium | Elementor Image Gallery | Cross-Site Scripting |
≤ 1.0.5 Fixed in 1.0.6 |
CVE-2024-53744 |
Patchstack | |
| 6.5 Medium | Elementor Button Plus | Cross-Site Scripting |
≤ 1.3.9 |
CVE-2024-53746 |
Patchstack | |
| 6.5 Medium | Post Carousel Slider for Elementor | Cross-Site Scripting |
≤ 1.5.0 Fixed in 1.6.0 |
CVE-2024-53749 |
Patchstack | |
| 6.5 Medium | Best Addons for Elementor | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.5 |
CVE-2024-53763 |
Patchstack | |
| 6.5 Medium | Softtemplates For Elementor | Cross-Site Scripting |
≤ 1.0.8 |
CVE-2024-53764 |
Patchstack | |
| 6.5 Medium | Devnex Addons For Elementor | Cross-Site Scripting |
≤ 1.0.9 |
CVE-2024-53766 |
Patchstack | |
| 6.5 Medium | Sparkle Elementor Kit | Cross-Site Scripting |
≤ 2.0.9 |
CVE-2024-53774 |
Patchstack | |
| 6.5 Medium | Cowidgets – Elementor Addons | Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) |
≤ 1.2.0 |
CVE-2024-53786 |
Patchstack | |
| 8.1 High | Cryptocurrency Widgets For Elementor | Local File Inclusion No login needed |
≤ 1.6.4 Fixed in 1.6.5 |
CVE-2024-53739 |
Patchstack | |
| 5.4 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS |
< 5.10.3 Fixed in 5.10.3 |
CVE-2024-10980 |
WPScan | |
| 7.5 High | Absolute Addons For Elementor | Local File Inclusion |
≤ 1.0.14 |
CVE-2024-52496 |
Patchstack | |
| 7.5 High | Shopready | Local File Inclusion |
≤ 3.6 |
CVE-2024-52497 |
Patchstack | |
| 7.5 High | Pricing table addon for elementor | Local File Inclusion |
≤ 1.0.0 |
CVE-2024-52499 |
Patchstack | |
| 4.3 Medium | Restaurant & Cafe Addon for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.5.9 |
CVE-2024-10780 |
Wordfence | |
| 4.3 Medium | Primary Addon for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.6.2 |
CVE-2024-10670 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.7.1003 |
CVE-2024-10798 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' |
≤ 4.1.3 |
CVE-2024-11203 |
Wordfence | |
| 5.4 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS |
< 5.10.3 Fixed in 5.10.3 |
CVE-2024-10493 |
WPScan | |
| 6.4 Medium | Elementor Website Builder – More than Just a Page Builder | Cross-Site Scripting More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.25.7 |
CVE-2024-8236 |
Wordfence | |
| 6.4 Medium | Jeg Elementor Kit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget |
≤ 2.6.9 |
CVE-2024-10308 |
Wordfence | |
| 4.3 Medium | Jeg Elementor Kit | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template |
≤ 2.6.9 |
CVE-2024-8899 |
Wordfence | |
| 7.3 High | Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation | Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed |
≤ 1.4 |
CVE-2024-11034 |
Wordfence | |
| 8.8 High | LA-Studio Element Kit for Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.4.2 |
CVE-2024-10873 |
Wordfence | |
| 4.3 Medium | Enter Addons – Ultimate Template Builder for Elementor | Information Disclosure Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post Disclosure |
≤ 2.1.9 |
CVE-2024-10868 |
Wordfence | |
| 8.1 High | Sky Addons – Elementor Addons with Widgets & Templates | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed |
≤ 2.6.1 |
CVE-2024-11601 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.