WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 851–900 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
4.3 Medium Stratum – Elementor Widgets Plugin Information Disclosure Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 1.4.4 CVE-2024-10316 Wordfence
4.3 Medium Sky Addons for Elementor Plugin sky-elementor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor Template ≤ 2.6.1 CVE-2024-9542 Wordfence
4.3 Medium Theme Builder For Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.2 CVE-2024-10782 Wordfence
4.3 Medium UltraAddons for Elementor Plugin ultraaddons-elementor-lite Broken Access Control Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) <= 1.1.8 - Insecure Direct Object Reference to Sensitive Information Exposure via UA_Template Shortcode ≤ 1.1.8 CVE-2024-10696 Wordfence
7.1 High Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.37 CVE-2024-52471 Patchstack
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.0.3 CVE-2024-10365 Wordfence
6.5 Medium Alley Elementor Widget Plugin alley-elementor-widget Cross-Site Scripting ≤ 1.0.7 CVE-2024-50521 Patchstack
6.5 Medium amazing neo icon font for elementor Plugin amazing-neo-icon-font-for-elementor Cross-Site Scripting ≤ 2.0.1 CVE-2024-50543 Patchstack
6.5 Medium RLM Elementor Widgets Pack Plugin rlm-elementor-widgets-pack Cross-Site Scripting ≤ 1.3.1 Fixed in 1.4.0 CVE-2024-50542 Patchstack
6.5 Medium Classy Addons for Elementor Plugin classy-addons-for-elementor Cross-Site Scripting ≤ 1.2.7 CVE-2024-50553 Patchstack
6.5 Medium Pro Addons For Elementor Plugin pro-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-51812 Patchstack
6.5 Medium Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51813 Patchstack
6.5 Medium Wezido Plugin wezido-elementor-addon-based-on-easy-digital-downloads Cross-Site Scripting ≤ 1.2 CVE-2024-51836 Patchstack
6.5 Medium File Select Control For Elementor Plugin file-select-control-for-elementor Cross-Site Scripting ≤ 1.3 CVE-2024-51841 Patchstack
6.5 Medium best bootstrap widgets for elementor Plugin best-bootstrap-widgets-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2024-51851 Patchstack
6.5 Medium Dynamic Post Grid Elementor Addon Plugin dynamic-post-grid-elementor-addon Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-51852 Patchstack
6.5 Medium Moose Elementor Kit Plugin moose-elementor-kit Cross-Site Scripting ≤ 1.0.0 Fixed in 1.1.0 CVE-2024-51856 Patchstack
6.5 Medium Ultimate Flipbox Addon for Elementor Plugin ultimate-flipbox-addon-for-elementor Cross-Site Scripting ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-51870 Patchstack
6.5 Medium Postify: Post Layout For Elementor Plugin postify-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-51893 Patchstack
6.5 Medium Topbar ID for Elementor Plugin topbar-id-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-51894 Patchstack
6.5 Medium Rig Elements For Elementor Plugin rig-elements Cross-Site Scripting ≤ 1.0 CVE-2024-51927 Patchstack
6.5 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-51938 Patchstack
6.5 Medium Drozd – Addons for Elementor Plugin drozd-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-52425 Patchstack
4.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Cross-Site Request Forgery All In One Form Integration including DB for Elementor <= 2.9.9.9 - Cross-Site Request Forgery No login needed ≤ 2.9.9.9 CVE-2024-6628 Wordfence
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 2.0.0 CVE-2024-9935 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
5.7 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 6.0.9 CVE-2024-8978 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.7 CVE-2024-8961 Wordfence
4.3 Medium Music Player for Elementor – Audio Player & Podcast Player Plugin music-player-for-elementor Broken Access Control Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Template Import ≤ 2.4.1 CVE-2024-10582 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation ≤ 2.1.5 CVE-2024-10897 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget ≤ 1.7.1001 CVE-2024-9682 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.7.1001 CVE-2024-9668 Wordfence
6.4 Medium Royal Elementor Addons and Template Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget ≤ 1.7.1001 CVE-2024-9059 Wordfence
4.3 Medium Boostify Header Footer Builder for Elementor Plugin boostify-header-footer-builder Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.3.6 CVE-2024-10794 Wordfence
6.1 Medium Razorpay Payment Button for Elementor Plugin razorpay-payment-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-10850 Wordfence
4.3 Medium BuddyPress Builder for Elementor – BuddyBuilder Plugin stax-buddy-builder Information Disclosure BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.7.4 CVE-2024-10778 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.18 CVE-2024-10323 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison ≤ 3.12.5 CVE-2024-10538 Wordfence
6.5 Medium Web Stories Widgets For Elementor Plugin shortcodes-for-amp-web-stories-and-elementor-widget Cross-Site Scripting ≤ 1.1 Fixed in 1.1.1 CVE-2024-52354 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-52356 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
6.5 Medium MasterBip para Elementor Plugin masterbip-for-elementor Cross-Site Scripting ≤ 1.6.3 CVE-2024-51571 Patchstack
6.5 Medium Extender All In One For Elementor Plugin extender-all-in-one-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2024-51575 Patchstack
6.5 Medium Clever Addons for Elementor Plugin cafe-lite Cross-Site Scripting ≤ 2.2.1 CVE-2024-51580 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-51581 Patchstack
6.5 Medium Marquee Elementor with Posts Plugin marquee-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2024-51584 Patchstack
6.5 Medium Sales Page Addon – Elementor & Beaver Builder Plugin sales-page-addon Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.4.5 CVE-2024-51585 Patchstack
6.5 Medium Definitive Addons for Elementor Plugin definitive-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.5.16 CVE-2024-51587 Patchstack
6.5 Medium Super Addons for Elementor Plugin super-addons-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2024-51588 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only