WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-85304 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Multiple Widgets 1.6.0 – < 1.7.4 Fixed in 1.7.4 CVE-2026-83547 WPScan
5.3 Medium Solace Extra Plugin solace-extra Information Disclosure Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content No login needed < 1.7.0 Fixed in 1.7.0 CVE-2026-16966 WPScan
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Authentication Bypass Bypass vulnerability No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-81777 Patchstack
6.8 Medium Royal Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Image Accordion Widget Effect Settings < 1.7.1066 Fixed in 1.7.1066 CVE-2026-19226 WPScan
5.3 Medium Royal Elementor Addons Plugin Information Disclosure Unauthenticated Taxonomy Term Disclosure No login needed < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13406 WPScan
5.3 Medium Royal Elementor Addons Plugin Broken Access Control Unauthenticated Like Count and IP Meta Modification via wpr_likes_init No login needed < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13404 WPScan
6.6 Medium Royal Elementor Addons Plugin Remote Code Execution Admin+ Remote Code Execution via Widget Builder < 1.7.1066 Fixed in 1.7.1066 CVE-2026-13405 WPScan
4.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control ≤ 1.2.6 CVE-2026-74003 Patchstack
5.4 Medium Royal Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget < 1.7.1065 Fixed in 1.7.1065 CVE-2026-19217 WPScan
6.5 Medium Ultimate Addons for Elementor Plugin ultimate-elementor Cross-Site Scripting ≤ 1.45.2 Fixed in 1.45.2.1 CVE-2026-66688 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-25403 Patchstack
5.3 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Content Injection Unauthenticated SMTP Header Injection No login needed ≤ 8.3.15 CVE-2026-0673 Wordfence
4.3 Medium Xpro Addons Plugin xpro-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function ≤ 1.5.1 CVE-2026-7105 Wordfence
6.8 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries SQL Injection Authenticated SQL Injection via id Parameter < 1.5.5 Fixed in 1.5.5 CVE-2026-14872 WPScan
5.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.15 Fixed in 2.0.16 CVE-2026-28147 Patchstack
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' ≤ 2.7.9.8 CVE-2026-12231 Wordfence
6.8 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes < 8.7.13 Fixed in 8.7.13 CVE-2026-14817 WPScan
6.1 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed < 51.1.76 Fixed in 51.1.76 CVE-2026-14841 WPScan
4.3 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script ≤ 3.1.1 CVE-2026-2916 Wordfence
5.3 Medium Essential Addons for Elementor - Lite Plugin Information Disclosure Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table No login needed < 6.6.10 Fixed in 6.6.10 CVE-2026-13345 WPScan
4.8 Medium Essential Addons for Elementor - Lite Plugin Cross-Site Scripting Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag < 6.6.10 Fixed in 6.6.10 CVE-2026-13344 WPScan
6.1 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed < 2.7.0 Fixed in 2.7.0 CVE-2026-13330 WPScan
5.3 Medium Persian Elementor (المنتور فارسی) Plugin persian-elementor Price Manipulation Unauthenticated Price Manipulation via ZarinPal Widget No login needed ≤ 2.8.1 CVE-2026-1982 Wordfence
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-66438 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-65433 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-59559 Patchstack
6.1 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Reflected XSS No login needed < 3.10.2 Fixed in 3.10.2 CVE-2026-14190 WPScan
5.9 Medium Custom links in Elementor Image Carousel Plugin custom-links-in-elementor-image-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2026-65534 Patchstack
5.3 Medium Graphina Plugin graphina-elementor-charts-and-graphs Broken Access Control No login needed ≤ 3.1.12 CVE-2026-65529 Patchstack
5.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65505 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-65503 Patchstack
5.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-65489 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.6.3 CVE-2026-65482 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.1.1 Fixed in 2.9.1.2 CVE-2026-65465 Patchstack
6.4 Medium Ultimate Addons for Elementor Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes ≤ 2.9.1 CVE-2026-15787 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget ≤ 6.6.11 CVE-2026-15145 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation ≤ 4.0.0 CVE-2026-1372 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings ≤ 6.6.11 CVE-2026-15156 Wordfence
4.9 Medium Elementor Plugin Information Disclosure Contributor+ Sensitive Information Disclosure via REST API < 4.1.4 Fixed in 4.1.4 CVE-2026-8825 WPScan
4.3 Medium W3SC Elementor to Zoho CRM Plugin w3sc-elementor-to-zoho Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.2.0 CVE-2026-9734 Wordfence
5.3 Medium Royal Elementor Addons Plugin Information Disclosure Unauthenticated Private Mega Menu Template Disclosure No login needed < 1.7.1063 Fixed in 1.7.1063 CVE-2026-13402 WPScan
6.1 Medium Header Footer Builder for Elementor Plugin header-footer-builder-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Template Import No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-12869 WPScan
6.4 Medium News Kit Addons For Elementor Plugin news-kit-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets ≤ 1.4.6 CVE-2026-11390 Wordfence
5.3 Medium JetBlocks For Elementor Plugin jet-blocks Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.0 Fixed in 1.5.0.1 CVE-2026-61976 Patchstack
5.0 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via Entry File Field No login needed < 1.5.2 Fixed in 1.5.2 CVE-2026-12081 WPScan
4.9 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter ≤ 4.11.84 CVE-2026-12141 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only