WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 190 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal No login needed ≤ 2.0.6 CVE-2026-4659 Wordfence
8.8 High Livemesh Addons by Elementor Plugin addons-for-elementor Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter ≤ 9.0 CVE-2026-1620 Wordfence
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
8.8 High Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' ≤ 1.6.4 CVE-2026-4326 Wordfence
7.1 High Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Cross-Site Scripting No login needed ≤ <= 2.0.1 Fixed in 2.0.2 CVE-2026-32532 Patchstack
8.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-25007 Patchstack
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass ≤ 1.7.1049 CVE-2025-13067 Wordfence
7.2 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Entry Fields No login needed ≤ 2.0.5 CVE-2026-2724 Wordfence
8.2 High Royal Elementor Addons Plugin royal-elementor-addons Other Other vulnerability Type No login needed ≤ 1.7.1052 Fixed in 1.7.1053 CVE-2026-28135 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
7.2 High WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1.5 CVE-2026-2568 Wordfence
8.8 High Master Addons for Elementor Premium Plugin master-addons Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via render_preview ≤ 2.1.3 CVE-2026-3132 Wordfence
8.1 High Eleblog – Elementor Blog And Magazine Addons Plugin ele-blog Local File Inclusion Elementor Blog And Magazine Addons plugin <= 2.0.3 - Local File Inclusion No login needed ≤ 2.0.3 CVE-2025-69374 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
8.8 High ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery PHP Object Injection ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68531 Patchstack
8.8 High Miraculous Elementor Plugin miraculous-el Authentication Bypass Broken Authentication ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-67998 Patchstack
7.2 High TableMaster for Elementor Plugin tablemaster-for-elementor Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter No login needed ≤ 1.3.6 CVE-2025-14610 Wordfence
7.5 High Kentha Elementor Widgets Plugin kentha-elementor Local File Inclusion ≤ 3.1 Fixed in 3.1 CVE-2026-24390 Patchstack
8.5 High Happy Addons for Elementor Plugin happy-elementor-addons SQL Injection ≤ 3.20.4 Fixed in 3.20.6 CVE-2025-68999 Patchstack
7.1 High AdForest Elementor Plugin adforest-elementor Cross-Site Scripting No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2025-67947 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.11.0 Fixed in 5.11.1 CVE-2025-69356 Patchstack
7.5 High PowerPack Pro for Elementor Plugin powerpack-elements Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 2.10.6 Fixed in 2.10.8 CVE-2024-24844 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68560 Patchstack
7.5 High Ultimate Member Widgets for Elementor Plugin ultimate-member-widgets-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-66116 Patchstack
8.8 High PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms PHP Object Injection ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60084 Patchstack
7.5 High Jobmonster Elementor Addon Plugin jobmonster-addon Local File Inclusion ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-67524 Patchstack
7.2 High Unlimited Elements For Elementor and Unlimited Elements For Elementor (Premium) Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 2.0 CVE-2025-13692 Wordfence
7.1 High TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting No login needed ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62041 Patchstack
8.8 High Multiple Plugins <= Multiple Versions Plugin image-hover-effects-elementor-addon Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Upload ≤ 1.0.2.2, ≤ 1.0.2.3, ≤ 1.0.3, … CVE-2025-10896 Wordfence
7.5 High Consulting Elementor Widgets Plugin consulting-elementor-widgets Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-64360 Patchstack
7.5 High Easy Elementor Addons Plugin easy-elementor-addons Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-58973 Patchstack
7.6 High Page Manager for Elementor Plugin page-manager-for-elementor Broken Access Control ≤ 2.0.5 CVE-2025-53230 Patchstack
7.5 High Devnex Addons For Elementor Plugin devnex-addons-for-elementor Local File Inclusion ≤ 1.0.9 CVE-2025-53339 Patchstack
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
7.1 High Universal Video Player Plugin elementor_widget_universal_video_player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-31057 Patchstack
7.6 High Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting ≤ 3.6.1 Fixed in 3.7.0 CVE-2025-49262 Patchstack
7.1 High WP Post Modules for Elementor Plugin wp-post-modules-el Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-31636 Patchstack
8.6 High Drag and Drop File Upload for Elementor Forms Plugin drag-and-drop-file-upload-for-elementor-forms Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2025-47492 Patchstack
7.5 High JetElements For Elementor Plugin jet-elements Broken Access Control No login needed ≤ 2.7.4.1 Fixed in 2.7.4.2 CVE-2025-39447 Patchstack
7.5 High JetBlocks For Elementor Plugin jet-blocks Broken Access Control No login needed ≤ 1.3.16 Fixed in 1.3.16.1 CVE-2025-39451 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
8.8 High Xpro Elementor Addons - Pro Plugin Remote Code Execution Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution ≤ 1.4.9 CVE-2024-13808 Wordfence
7.5 High CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon Plugin Path Traversal HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon <= 2.4 - Unauthenticated Arbitrary File Read No login needed ≤ 2.4 CVE-2025-3103 Wordfence
7.1 High HT Event Plugin ht-event Cross-Site Scripting WordPress Event Manager Plugin for Elementor Plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-24624 Patchstack
7.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.14 Fixed in 6.0.15 CVE-2025-24752 Patchstack
8.1 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-32672 Patchstack
7.5 High aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32158 Patchstack
7.6 High Split Test For Elementor Plugin split-test-for-elementor SQL Injection ≤ 1.8.3 Fixed in 1.8.4 CVE-2025-32204 Patchstack
7.5 High Sparkle Elementor Kit Plugin sparkle-elementor-kit Local File Inclusion ≤ 2.0.9 CVE-2025-32157 Patchstack
7.5 High The Pack Elementor addons Plugin the-pack-addon Local File Inclusion ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-30845 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only