WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,251–1,300 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.26 CVE-2024-2618 Wordfence
8.0 High 140+ Widgets | Best Addons For Elementor – FREE Plugin xpro-elementor-addons PHP Object Injection FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection ≤ 1.4.3.1 CVE-2024-4471 Wordfence
4.3 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Broken Access Control Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual ≤ 3.9.12 CVE-2024-1803 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Menu and Shape Divider ≤ 4.10.31 CVE-2024-4378 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pagepiling Widget ≤ 3.14.1 CVE-2024-3997 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via data[post_ids][0] ≤ 1.5.107 CVE-2024-4779 Wordfence
5.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control Missing Authorization via export_entries, rtformnewform, and rtformupdate No login needed ≤ 1.1.5 CVE-2023-6325 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.3.7.6 CVE-2024-4431 Wordfence
6.4 Medium Awesome Contact Form7 for Elementor Plugin awesome-contact-form7-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via AEP Contact Form 7 Widget ≤ 2.9 CVE-2024-4486 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes ≤ 5.6.1 CVE-2024-3926 Wordfence
6.4 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widget Attributes ≤ 2.4.28 CVE-2024-4262 Wordfence
6.4 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter ≤ 1.0.9 CVE-2024-4896 Wordfence
9.8 Critical WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.1.37 CVE-2024-5147 Wordfence
5.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Other Form Submission Admin Email Bypass No login needed ≤ 5.6.3 CVE-2024-3927 Wordfence
6.4 Medium Elegant Addons for elementor Plugin elegant-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML tags ≤ 1.0.8 CVE-2024-3066 Wordfence
6.4 Medium Elegant Addons for elementor Plugin elegant-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Switcher, Slider, and Iconbox Widgets ≤ 1.0.8 CVE-2024-5092 Wordfence
6.4 Medium Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced Plugin toolbar-extras Cross-Site Scripting WordPress Admin Bar Enhanced <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.9 CVE-2024-3611 Wordfence
6.4 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Parameters ≤ 2.5.9 CVE-2024-4980 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.21.5 CVE-2024-4619 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5.2 CVE-2024-4876 Wordfence
6.4 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.3.1 CVE-2024-4695 Wordfence
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Broken Access Control Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update ≤ 2.5.2 CVE-2024-4875 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.8 CVE-2024-5088 Wordfence
6.4 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.4.26 CVE-2024-4432 Wordfence
6.4 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.1.1 CVE-2024-4698 Wordfence
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.1.3 CVE-2024-4374 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter ≤ 3.10.8 CVE-2024-4865 Wordfence
4.3 Medium Integration for Contact Form 7 and Salesforce Plugin cf7-salesforce Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34755 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Authentication Bypass IP Bypass No login needed ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-32786 Patchstack
8.5 High Elementor Website Builder Plugin elementor Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization ≤ 3.19.0 Fixed in 3.19.1 CVE-2024-24934 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.20 Fixed in 1.36.21 CVE-2023-50890 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion ≤ 1.6.3 Fixed in 1.6.4 CVE-2023-47679 Patchstack
8.6 High The Plus Addons for Elementor Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.2.8 Fixed in 5.2.9 CVE-2023-47178 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Contributor+ Privilege Escalation ≤ 5.8.8 Fixed in 5.8.9 CVE-2023-41955 Patchstack
9.8 Critical HT Mega Plugin ht-mega-for-elementor Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-37999 Patchstack
6.5 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2024-34575 Patchstack
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-3134 Wordfence
5.0 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Content Injection Authenticated (Author+) HTML Injection ≤ 1.6.26 CVE-2024-2619 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-4580 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.28 CVE-2024-4634 Wordfence
6.4 Medium Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 3.10.7 CVE-2024-4391 Wordfence
5.4 Medium Royal Elementor Addons and Templates Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget ≤ 1.3.974 CVE-2024-3887 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget ≤ 3.10.7 CVE-2024-4478 Wordfence
6.4 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 1.2.1 CVE-2024-4702 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-site Scriping via 'Sina Particle Layer' ≤ 3.5.3 CVE-2024-4373 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget ≤ 2.6.9.6 CVE-2024-4618 Wordfence
6.4 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget ≤ 1.1.36 CVE-2024-4370 Wordfence
6.4 Medium Borderless - Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.3 CVE-2024-4666 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Cross-Site Scripting ≤ 3.5.3 CVE-2024-4333 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.20 CVE-2024-4624 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only