WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 801–850 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Rife Elementor Extensions & Templates Plugin rife-elementor-extensions Broken Access Control ≤ 1.1.10 Fixed in 1.2.0 CVE-2023-27454 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2023-47826 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Broken Access Control No login needed ≤ 2.1.10 Fixed in 2.2 CVE-2023-48750 Patchstack
5.4 Medium Elementor Timeline Widget Plugin 3r-elementor-timeline-widget Broken Access Control Notice Dismissal ≤ 2.2 Fixed in 2.3 CVE-2023-49755 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2023-50884 Patchstack
5.3 Medium Metform Plugin metform Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2023-50903 Patchstack
6.1 Medium Smoove connector for Elementor forms Plugin smoove-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.0 CVE-2024-11367 Wordfence
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-53796 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.14 Fixed in 6.0.1 CVE-2024-53823 Patchstack
5.9 Medium Borderless Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin <= 1.5.8 - Cross Site Scripting (XSS) ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54211 Patchstack
6.5 Medium Advanced Element Bucket Addons for Elementor Plugin cs-element-bucket Cross-Site Scripting ≤ 1.0.2 CVE-2024-54210 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54212 Patchstack
4.3 Medium PowerPack Elementor Addons (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.8.1 CVE-2024-10692 Wordfence
4.3 Medium XLTab – Accordions and Tabs for Elementor Page Builder Plugin xl-tab Information Disclosure Accordions and Tabs for Elementor Page Builder <= 1.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.4 CVE-2024-10689 Wordfence
4.3 Medium Gold Addons for Elementor Plugin gold-addons-for-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) License Activation/Deactivation ≤ 1.3.2 CVE-2024-12110 Wordfence
4.3 Medium AnyWhere Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.11 CVE-2024-10777 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.5.2 CVE-2024-8962 Wordfence
4.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.4.4 CVE-2024-10787 Wordfence
4.3 Medium Eleblog – Elementor Blog And Magazine Addons Plugin ele-blog Broken Access Control Elementor Blog And Magazine Addons <= 1.8 - Missing Authorization to Authenticated (Subscriber+) Deactivation Submission ≤ 1.8 CVE-2024-10663 Wordfence
4.3 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.3.3 CVE-2024-12062 Wordfence
6.4 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget ≤ 5.10.5 CVE-2024-9058 Wordfence
6.4 Medium CMSMasters Elementor Addon Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.14.7 CVE-2024-9694 Wordfence
6.5 Medium Elementor Portfolio Builder Plugin portfolio-builder-elementor Cross-Site Scripting ≤ 1.0.0 CVE-2024-52486 Patchstack
6.5 Medium Generic Elements Plugin generic-elements-for-elementor Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-53709 Patchstack
6.5 Medium Countdown Timer for Elementor Plugin countdown-timer-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-53743 Patchstack
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
6.5 Medium Elementor Button Plus Plugin fd-elementor-button-plus Cross-Site Scripting ≤ 1.3.9 CVE-2024-53746 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
6.5 Medium Best Addons for Elementor Plugin best-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2024-53763 Patchstack
6.5 Medium Softtemplates For Elementor Plugin softtemplates-for-elementor Cross-Site Scripting ≤ 1.0.8 CVE-2024-53764 Patchstack
6.5 Medium Devnex Addons For Elementor Plugin devnex-addons-for-elementor Cross-Site Scripting ≤ 1.0.9 CVE-2024-53766 Patchstack
6.5 Medium Sparkle Elementor Kit Plugin sparkle-elementor-kit Cross-Site Scripting ≤ 2.0.9 CVE-2024-53774 Patchstack
6.5 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2024-53786 Patchstack
8.1 High Cryptocurrency Widgets For Elementor Plugin cryptocurrency-widgets-for-elementor Local File Inclusion No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-53739 Patchstack
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10980 WPScan
7.5 High Absolute Addons For Elementor Plugin absolute-addons Local File Inclusion ≤ 1.0.14 CVE-2024-52496 Patchstack
7.5 High Shopready Plugin shopready-elementor-addon Local File Inclusion ≤ 3.6 CVE-2024-52497 Patchstack
7.5 High Pricing table addon for elementor Plugin pricing-table-addon-for-elementor Local File Inclusion ≤ 1.0.0 CVE-2024-52499 Patchstack
4.3 Medium Restaurant & Cafe Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.5.9 CVE-2024-10780 Wordfence
4.3 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.6.2 CVE-2024-10670 Wordfence
4.3 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.7.1003 CVE-2024-10798 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' ≤ 4.1.3 CVE-2024-11203 Wordfence
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10493 WPScan
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.25.7 CVE-2024-8236 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget ≤ 2.6.9 CVE-2024-10308 Wordfence
4.3 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template ≤ 2.6.9 CVE-2024-8899 Wordfence
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
8.8 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.4.2 CVE-2024-10873 Wordfence
4.3 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Information Disclosure Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post Disclosure ≤ 2.1.9 CVE-2024-10868 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only