WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 2.4.9 CVE-2024-3307 Wordfence
6.4 Medium Fancy Elementor Flipbox Plugin fancy-elementor-flipbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Elementor Flipbox Widget ≤ 2.5.1 CVE-2024-2349 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 3.10.5 CVE-2024-3891 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes ≤ 5.4.2 CVE-2024-3197 Wordfence
7.2 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.8 CVE-2024-3715 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 5.4.2 CVE-2024-3199 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting ≤ 2.0.5.9 CVE-2024-4265 Wordfence
6.4 Medium ElementsKit Elementor addons and Templates Library Plugin elementskit-lite Cross-Site Scripting The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insuff… 3.0.7 – 3.1.2 CVE-2024-3650 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox Widget ≤ 2.4.6 CVE-2024-2084 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline ≤ 3.10.4 CVE-2024-3724 Wordfence
8.2 High Royal Elementor Addons and Templates Plugin royal-elementor-addons Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.3.94 CVE-2024-1567 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title ≤ 2.6.9.4 CVE-2024-3489 Wordfence
5.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Broken Access Control All In One Form Integration including DB for Elementor <= 2.9.9.7 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 2.9.9.7 CVE-2024-2043 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module ≤ 3.1.0 CVE-2024-3499 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id ≤ 2.8.7 CVE-2024-3991 Wordfence
7.5 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Information Disclosure Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products No login needed ≤ 2.4.6 CVE-2023-6214 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ ≤ 2.4.8 CVE-2024-2790 Wordfence
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.10.30 CVE-2024-4203 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'arrow_style' ≤ 4.10.28 CVE-2024-3647 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 2.6.4 CVE-2024-3161 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner ≤ 2.6.4 CVE-2024-3819 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.10.28 CVE-2024-3885 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget ≤ 2.4.9 CVE-2024-3308 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes ≤ 1.3.971 CVE-2024-3675 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 2.6.9.3 CVE-2024-2750 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid ≤ 2.6.9.2 CVE-2024-2503 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.17 CVE-2024-4156 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action ≤ 2.6.9.4 CVE-2024-3985 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.15 CVE-2024-4003 Wordfence
4.3 Medium Easy Restaurant Table Booking Plugin fd-elementor-imagebox Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2024-4083 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' ≤ 2.4.6 CVE-2024-2085 Wordfence
6.4 Medium Elementor ImageBox Plugin fd-elementor-imagebox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.8 CVE-2024-3074 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget ≤ 1.3.7.5 CVE-2024-3005 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributes ≤ 2.6.4 CVE-2024-0334 Wordfence
4.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on Duplicate Post ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-33595 Patchstack
7.5 High Piotnet Addons For Elementor Pro Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 7.1.17 CVE-2024-33635 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 7.1.17 CVE-2024-33634 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Cross-Site Request Forgery No login needed ≤ 7.1.17 CVE-2024-33632 Patchstack
6.5 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting ≤ 1.1.35 Fixed in 1.1.36 CVE-2024-33539 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.26 CVE-2024-33630 Patchstack
6.5 Medium Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 7.1.17 CVE-2024-33631 Patchstack
7.1 High Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.17 CVE-2024-33633 Patchstack
6.5 Medium Opal Widgets For Elementor Plugin opal-widgets-for-elementor Cross-Site Scripting ≤ 1.6.9 CVE-2024-33649 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown widget ≤ 1.7.0 CVE-2024-3309 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget ≤ 3.10.6 CVE-2024-3890 Wordfence
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure No login needed ≤ 5.9.15 CVE-2024-3733 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Sina Fancy Text Widget ≤ 3.5.2 CVE-2024-3988 Wordfence
6.5 Medium Elementor Website Builder Plugin elementor Authentication Bypass Auth. Arbitrary Attachment Read ≤ 3.16.4 Fixed in 3.16.5 CVE-2023-47504 Patchstack
9.9 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.60 Fixed in 1.5.61 CVE-2023-31090 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only