WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Unauthenticated Popup Deactivation via jltma_popup_disable_expired No login needed 3.0.0 – < 3.1.9 Fixed in 3.1.9 CVE-2026-91015 WPScan
6.1 Medium Royal Elementor Addons Plugin Content Injection Unauthenticated Stored HTML Injection in Form Notification Emails No login needed < 1.7.1067 Fixed in 1.7.1067 CVE-2026-13407 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget < 1.7.9 Fixed in 1.7.9 CVE-2026-84088 WPScan
6.8 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Editor+ SQL Injection via Elementor Category and Location Widget Settings ≤ 1.5.7 CVE-2026-16593 WPScan
6.4 Medium ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets Plugin shopengine Cross-Site Scripting All in One WooCommerce Solution with eCommerce Templates & Woo Widgets <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter ≤ 4.9.5 CVE-2026-85575 Wordfence
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed ≤ 1.7.1066 CVE-2026-17585 Wordfence
7.1 High Master Addons for Elementor Plugin master-addons Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-62089 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
7.6 High Sky Addons for Elementor Plugin sky-elementor-addons SQL Injection ≤ 3.8.4 Fixed in 3.8.5 CVE-2026-62109 Patchstack
5.3 Medium Persian Elementor Plugin Price Manipulation Unauthenticated ZarinPal Payment Callback Authority Bypass No login needed 2.7.10 – < 2.8.2 Fixed in 2.8.2 CVE-2026-86809 WPScan
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.16 CVE-2026-18561 Wordfence
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.16 CVE-2026-77150 Wordfence
9.8 Critical Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'type' Parameter No login needed ≤ 1.6.0 CVE-2026-18351 Wordfence
6.8 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Table Widget 3.7.1 – < 3.10.4 Fixed in 3.10.4 CVE-2026-83541 WPScan
6.4 Medium Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting ≤ 3.1.11 CVE-2026-13709 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
6.1 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'formData[id]' Parameter No login needed ≤ 2.0.17 CVE-2026-75586 Wordfence
6.8 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Contributor+ Stored XSS via Magazine Grid Widget < 51.1.77 Fixed in 51.1.77 CVE-2026-84896 WPScan
5.3 Medium Xpro Elementor Addons Plugin Information Disclosure Unauthenticated Draft/Private Product Disclosure via Quick View No login needed < 1.7.8 Fixed in 1.7.8 CVE-2026-84146 WPScan
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-85304 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
7.1 High RTMKit Plugin rometheme-for-elementor Cross-Site Scripting No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84763 Patchstack
8.8 High RTMKit Plugin rometheme-for-elementor PHP Object Injection ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84752 Patchstack
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Multiple Widgets 1.6.0 – < 1.7.4 Fixed in 1.7.4 CVE-2026-83547 WPScan
5.3 Medium Solace Extra Plugin solace-extra Information Disclosure Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content No login needed < 1.7.0 Fixed in 1.7.0 CVE-2026-16966 WPScan
7.2 High Master Addons for Elementor Plugin master-addons Broken Access Control Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction ≤ 3.1.9 CVE-2026-75921 Wordfence
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Authentication Bypass Bypass vulnerability No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-81777 Patchstack
6.8 Medium Royal Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Image Accordion Widget Effect Settings < 1.7.1066 Fixed in 1.7.1066 CVE-2026-19226 WPScan
5.3 Medium Royal Elementor Addons Plugin Information Disclosure Unauthenticated Taxonomy Term Disclosure No login needed < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13406 WPScan
5.3 Medium Royal Elementor Addons Plugin Broken Access Control Unauthenticated Like Count and IP Meta Modification via wpr_likes_init No login needed < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13404 WPScan
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
9.3 Critical TheGem (Elementor) Theme thegem-elementor SQL Injection No login needed ≤ 5.12.3 Fixed in 5.12.3.1 CVE-2026-66609 Patchstack
6.6 Medium Royal Elementor Addons Plugin Remote Code Execution Admin+ Remote Code Execution via Widget Builder < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13405 WPScan
9.0 Critical Elementor Pro Plugin elementor-pro Arbitrary File Upload No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-32475 Patchstack
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
4.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control ≤ 1.2.6 CVE-2026-74003 Patchstack
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.2 High PDF Smart Viewer for Elementor Plugin pdf-smart-viewer-for-elementor Server-Side Request Forgery No login needed ≤ 1.0.4 CVE-2026-32473 Patchstack
9.6 Critical Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Arbitrary File Upload No login needed ≤ 7.1.67 CVE-2026-28192 Patchstack
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting ≤ 1.7.1064 CVE-2026-17123 Wordfence
8.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment No login needed 5.8.6 – < 6.7.2 Fixed in 6.7.2 CVE-2026-18039 WPScan
5.4 Medium Royal Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget < 1.7.1065 Fixed in 1.7.1065 CVE-2026-19217 WPScan
6.5 Medium Ultimate Addons for Elementor Plugin ultimate-elementor Cross-Site Scripting ≤ 1.45.2 Fixed in 1.45.2.1 CVE-2026-66688 Patchstack
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit PHP Object Injection ≤ 3.2.10 Fixed in 3.2.11 CVE-2026-65549 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only