WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–100 of 1,359 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Broken Access Control No login needed |
≤ 2.0.17 Fixed in 2.0.18 |
CVE-2026-85304 |
Patchstack | |
| 6.5 Medium | WPKoi Templates for Elementor | Cross-Site Scripting |
≤ 3.7.2 Fixed in 3.7.3 |
CVE-2026-85302 |
Patchstack | |
| 6.8 Medium | Xpro Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Multiple Widgets |
1.6.0 – < 1.7.4 Fixed in 1.7.4 |
CVE-2026-83547 |
WPScan | |
| 5.3 Medium | Solace Extra | Information Disclosure Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2026-16966 |
WPScan | |
| 5.3 Medium | Essential Addons for Elementor | Authentication Bypass Bypass vulnerability No login needed |
≤ 6.8.0 Fixed in 6.8.1 |
CVE-2026-81777 |
Patchstack | |
| 6.8 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Image Accordion Widget Effect Settings |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-19226 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Information Disclosure Unauthenticated Taxonomy Term Disclosure No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13406 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Broken Access Control Unauthenticated Like Count and IP Meta Modification via wpr_likes_init No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13404 |
WPScan | |
| 6.6 Medium | Royal Elementor Addons | Remote Code Execution Admin+ Remote Code Execution via Widget Builder |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13405 |
WPScan | |
| 4.3 Medium | RomethemeForm For Elementor | Broken Access Control |
≤ 1.2.6 |
CVE-2026-74003 |
Patchstack | |
| 5.4 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget |
< 1.7.1065 Fixed in 1.7.1065 |
CVE-2026-19217 |
WPScan | |
| 6.5 Medium | Ultimate Addons for Elementor | Cross-Site Scripting |
≤ 1.45.2 Fixed in 1.45.2.1 |
CVE-2026-66688 |
Patchstack | |
| 5.3 Medium | Element Pack Elementor Addons | Authentication Bypass Captcha Bypass No login needed |
≤ 8.7.13 Fixed in 8.7.14 |
CVE-2026-65502 |
Patchstack | |
| 6.5 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Path Traversal Arbitrary File Download |
≤ 2.0.14 Fixed in 2.0.15 |
CVE-2026-28146 |
Patchstack | |
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Broken Access Control No login needed |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-25403 |
Patchstack | |
| 5.3 Medium | Element Pack Addons for Elementor | Content Injection Unauthenticated SMTP Header Injection No login needed |
≤ 8.3.15 |
CVE-2026-0673 |
Wordfence | |
| 4.3 Medium | Xpro Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function |
≤ 1.5.1 |
CVE-2026-7105 |
Wordfence | |
| 6.8 Medium | Database for Contact Form 7, WPforms, Elementor forms | SQL Injection Authenticated SQL Injection via id Parameter |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-14872 |
WPScan | |
| 5.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Broken Access Control |
≤ 2.0.15 Fixed in 2.0.16 |
CVE-2026-28147 |
Patchstack | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' |
≤ 2.7.9.8 |
CVE-2026-12231 |
Wordfence | |
| 6.8 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes |
< 8.7.13 Fixed in 8.7.13 |
CVE-2026-14817 |
WPScan | |
| 6.1 Medium | King Addons for Elementor | Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed |
< 51.1.76 Fixed in 51.1.76 |
CVE-2026-14841 |
WPScan | |
| 4.3 Medium | Jeg Kit for Elementor | Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script |
≤ 3.1.1 |
CVE-2026-2916 |
Wordfence | |
| 5.3 Medium | Essential Addons for Elementor - Lite | Information Disclosure Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table No login needed |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13345 |
WPScan | |
| 4.8 Medium | Essential Addons for Elementor - Lite | Cross-Site Scripting Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13344 |
WPScan | |
| 6.1 Medium | Animation Addons for Elementor | Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed |
< 2.7.0 Fixed in 2.7.0 |
CVE-2026-13330 |
WPScan | |
| 5.3 Medium | Persian Elementor (المنتور فارسی) | Price Manipulation Unauthenticated Price Manipulation via ZarinPal Widget No login needed |
≤ 2.8.1 |
CVE-2026-1982 |
Wordfence | |
| 5.3 Medium | Exclusive Addons Elementor | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2026-66438 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-65433 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-59559 |
Patchstack | |
| 6.1 Medium | Sina Extension for Elementor | Cross-Site Scripting Reflected XSS No login needed |
< 3.10.2 Fixed in 3.10.2 |
CVE-2026-14190 |
WPScan | |
| 5.9 Medium | Custom links in Elementor Image Carousel | Cross-Site Scripting |
≤ 1.1.1 |
CVE-2026-65534 |
Patchstack | |
| 5.3 Medium | Graphina | Broken Access Control No login needed |
≤ 3.1.12 |
CVE-2026-65529 |
Patchstack | |
| 5.3 Medium | Ultimate Store Kit Elementor Addons | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-65505 |
Patchstack | |
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Cross-Site Scripting |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-65503 |
Patchstack | |
| 5.3 Medium | LA-Studio Element Kit for Elementor | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-65489 |
Patchstack | |
| 6.5 Medium | LA-Studio Element Kit for Elementor | Cross-Site Scripting |
≤ 1.6.3 |
CVE-2026-65482 |
Patchstack | |
| 6.5 Medium | JetElements For Elementor | Cross-Site Scripting |
≤ 2.9.1.1 Fixed in 2.9.1.2 |
CVE-2026-65465 |
Patchstack | |
| 6.4 Medium | Ultimate Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes |
≤ 2.9.1 |
CVE-2026-15787 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
≤ 6.6.11 |
CVE-2026-15145 |
Wordfence | |
| 4.3 Medium | Tutor LMS Elementor Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation |
≤ 4.0.0 |
CVE-2026-1372 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings |
≤ 6.6.11 |
CVE-2026-15156 |
Wordfence | |
| 4.9 Medium | Elementor | Information Disclosure Contributor+ Sensitive Information Disclosure via REST API |
< 4.1.4 Fixed in 4.1.4 |
CVE-2026-8825 |
WPScan | |
| 4.3 Medium | W3SC Elementor to Zoho CRM | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 2.2.0 |
CVE-2026-9734 |
Wordfence | |
| 5.3 Medium | Royal Elementor Addons | Information Disclosure Unauthenticated Private Mega Menu Template Disclosure No login needed |
< 1.7.1063 Fixed in 1.7.1063 |
CVE-2026-13402 |
WPScan | |
| 6.1 Medium | Header Footer Builder for Elementor | Cross-Site Scripting Contributor+ Stored XSS via Template Import No login needed |
< 1.2.1 Fixed in 1.2.1 |
CVE-2026-12869 |
WPScan | |
| 6.4 Medium | News Kit Addons For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets |
≤ 1.4.6 |
CVE-2026-11390 |
Wordfence | |
| 5.3 Medium | JetBlocks For Elementor | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.5.0 Fixed in 1.5.0.1 |
CVE-2026-61976 |
Patchstack | |
| 5.0 Medium | Database for Contact Form 7, WPforms, Elementor forms | PHP Object Injection Unauthenticated PHP Object Injection via Entry File Field No login needed |
< 1.5.2 Fixed in 1.5.2 |
CVE-2026-12081 |
WPScan | |
| 4.9 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter |
≤ 4.11.84 |
CVE-2026-12141 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.