WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 1,616 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Path Traversal Arbitrary File Download |
≤ 2.0.14 Fixed in 2.0.15 |
CVE-2026-28146 |
Patchstack | |
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Broken Access Control No login needed |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-25403 |
Patchstack | |
| 5.3 Medium | Element Pack Addons for Elementor | Content Injection Unauthenticated SMTP Header Injection No login needed |
≤ 8.3.15 |
CVE-2026-0673 |
Wordfence | |
| 4.3 Medium | Xpro Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function |
≤ 1.5.1 |
CVE-2026-7105 |
Wordfence | |
| 6.8 Medium | Database for Contact Form 7, WPforms, Elementor forms | SQL Injection Authenticated SQL Injection via id Parameter |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-14872 |
WPScan | |
| 5.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Broken Access Control |
≤ 2.0.15 Fixed in 2.0.16 |
CVE-2026-28147 |
Patchstack | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' |
≤ 2.7.9.8 |
CVE-2026-12231 |
Wordfence | |
| 6.8 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes |
< 8.7.13 Fixed in 8.7.13 |
CVE-2026-14817 |
WPScan | |
| 6.1 Medium | King Addons for Elementor | Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed |
< 51.1.76 Fixed in 51.1.76 |
CVE-2026-14841 |
WPScan | |
| 4.3 Medium | Jeg Kit for Elementor | Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script |
≤ 3.1.1 |
CVE-2026-2916 |
Wordfence | |
| 8.8 High | DynamicKit for Elementor | Privilege Escalation Unauthenticated Account Takeover via Password Reset Link Host Injection No login needed |
< 1.0.3 Fixed in 1.0.3 |
CVE-2026-14596 |
WPScan | |
| 5.3 Medium | Essential Addons for Elementor - Lite | Information Disclosure Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table No login needed |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13345 |
WPScan | |
| 4.8 Medium | Essential Addons for Elementor - Lite | Cross-Site Scripting Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13344 |
WPScan | |
| 6.1 Medium | Animation Addons for Elementor | Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed |
< 2.7.0 Fixed in 2.7.0 |
CVE-2026-13330 |
WPScan | |
| 5.3 Medium | Persian Elementor (المنتور فارسی) | Price Manipulation Unauthenticated Price Manipulation via ZarinPal Widget No login needed |
≤ 2.8.1 |
CVE-2026-1982 |
Wordfence | |
| 7.1 High | Database for Contact Form 7, WPforms, Elementor forms | Cross-Site Scripting Reflected XSS via form_id No login needed |
< 1.5.3 Fixed in 1.5.3 |
CVE-2026-14870 |
WPScan | |
| 5.3 Medium | Exclusive Addons Elementor | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2026-66438 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-65433 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-59559 |
Patchstack | |
| 6.1 Medium | Sina Extension for Elementor | Cross-Site Scripting Reflected XSS No login needed |
< 3.10.2 Fixed in 3.10.2 |
CVE-2026-14190 |
WPScan | |
| 5.9 Medium | Custom links in Elementor Image Carousel | Cross-Site Scripting |
≤ 1.1.1 |
CVE-2026-65534 |
Patchstack | |
| 5.3 Medium | Graphina | Broken Access Control No login needed |
≤ 3.1.12 |
CVE-2026-65529 |
Patchstack | |
| 5.3 Medium | Ultimate Store Kit Elementor Addons | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-65505 |
Patchstack | |
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Cross-Site Scripting |
≤ 3.0.5 Fixed in 3.0.7 |
CVE-2026-65503 |
Patchstack | |
| 5.3 Medium | LA-Studio Element Kit for Elementor | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-65489 |
Patchstack | |
| 7.1 High | LA-Studio Element Kit for Elementor | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2026-65488 |
Patchstack | |
| 6.5 Medium | LA-Studio Element Kit for Elementor | Cross-Site Scripting |
≤ 1.6.3 |
CVE-2026-65482 |
Patchstack | |
| 6.5 Medium | JetElements For Elementor | Cross-Site Scripting |
≤ 2.9.1.1 Fixed in 2.9.1.2 |
CVE-2026-65465 |
Patchstack | |
| 6.4 Medium | Ultimate Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes |
≤ 2.9.1 |
CVE-2026-15787 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
≤ 6.6.11 |
CVE-2026-15145 |
Wordfence | |
| 4.3 Medium | Tutor LMS Elementor Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation |
≤ 4.0.0 |
CVE-2026-1372 |
Wordfence | |
| 8.8 High | CRT Addons for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Contact Form No login needed |
< 1.6.7 Fixed in 1.6.7 |
CVE-2026-11767 |
WPScan | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings |
≤ 6.6.11 |
CVE-2026-15156 |
Wordfence | |
| 4.9 Medium | Elementor | Information Disclosure Contributor+ Sensitive Information Disclosure via REST API |
< 4.1.4 Fixed in 4.1.4 |
CVE-2026-8825 |
WPScan | |
| 8.8 High | Unlimited Elements for Elementor | Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed |
< 2.0.11 Fixed in 2.0.11 |
CVE-2026-10081 |
WPScan | |
| 4.3 Medium | W3SC Elementor to Zoho CRM | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 2.2.0 |
CVE-2026-9734 |
Wordfence | |
| 5.3 Medium | Royal Elementor Addons | Information Disclosure Unauthenticated Private Mega Menu Template Disclosure No login needed |
< 1.7.1063 Fixed in 1.7.1063 |
CVE-2026-13402 |
WPScan | |
| 2.7 Low | RTMKit Addons for Elementor | Broken Access Control Author+ Site-Wide Theme Builder Template Creation and Activation |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-12907 |
WPScan | |
| 2.7 Low | RTMKit Addons for Elementor | Information Disclosure Contributor+ Private Post Title Disclosure |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-12906 |
WPScan | |
| 6.1 Medium | Header Footer Builder for Elementor | Cross-Site Scripting Contributor+ Stored XSS via Template Import No login needed |
< 1.2.1 Fixed in 1.2.1 |
CVE-2026-12869 |
WPScan | |
| 6.4 Medium | News Kit Addons For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets |
≤ 1.4.6 |
CVE-2026-11390 |
Wordfence | |
| 5.3 Medium | JetBlocks For Elementor | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.5.0 Fixed in 1.5.0.1 |
CVE-2026-61976 |
Patchstack | |
| 7.5 High | TheGem Theme Elements (for Elementor) | Local File Inclusion |
< 5.12.1.1 Fixed in 5.12.1.1 |
CVE-2026-57804 |
Patchstack | |
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting No login needed |
≤ 2.0.12 Fixed in 2.0.13 |
CVE-2026-57718 |
Patchstack | |
| 7.1 High | ElementInvader Addons for Elementor | Cross-Site Scripting No login needed |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2026-57376 |
Patchstack | |
| 5.0 Medium | Database for Contact Form 7, WPforms, Elementor forms | PHP Object Injection Unauthenticated PHP Object Injection via Entry File Field No login needed |
< 1.5.2 Fixed in 1.5.2 |
CVE-2026-12081 |
WPScan | |
| 8.8 High | Essential Addons for Elementor | Privilege Escalation Authenticated (Contributor+) Account Takeover via Email Header Injection |
≤ 6.6.10 |
CVE-2026-15155 |
Wordfence | |
| 4.9 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter |
≤ 4.11.84 |
CVE-2026-12141 |
Wordfence | |
| 7.5 High | LA-Studio Element Kit for Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting |
≤ 1.6.1 |
CVE-2026-15338 |
Wordfence | |
| 6.4 Medium | Jeg Kit for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget |
≤ 3.2.6 |
CVE-2026-13710 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.