WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 337 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rael_title_tag' ≤ 1.6.9 CVE-2025-2225 Wordfence
7.5 High aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-32158 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.36 CVE-2025-32197 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-31567 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2025-22646 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 3.5 Fixed in 3.6 CVE-2025-30812 Patchstack
5.7 Medium Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Information Disclosure Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 1.6.8 CVE-2025-2228 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets ≤ 2.7.6 CVE-2025-1571 Wordfence
8.8 High Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Local File Inclusion Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.4 CVE-2024-13353 Wordfence
4.3 Medium Prime Addons for Elementor Plugin prime-addons-for-elementor Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference via pae_global_block Shortcode ≤ 2.0.1 CVE-2024-13855 Wordfence
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-26769 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.7 CVE-2024-13699 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.12 CVE-2024-13547 Wordfence
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-24729 Patchstack
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-24618 Patchstack
6.5 Medium All Embed – Elementor Addons Plugin all-embed-addons-for-elementor Cross-Site Scripting Elementor Addons plugin <= 1.1.3 - Cross Site Scripting (XSS) ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-24595 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-24578 Patchstack
4.3 Medium Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates Plugin sastra-essential-addons-for-elementor Broken Access Control Free Elementor Addons, Widgets and Templates <= 1.0.14 - Missing Authorization to Spexo Theme Install ≤ 1.0.14 CVE-2024-13335 Wordfence
6.5 Medium Elementor AI Addons Plugin ai-addons-for-elementor Cross-Site Scripting ≤ 2.2.1 CVE-2025-22758 Patchstack
7.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Local File Inclusion ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-22786 Patchstack
4.3 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.4.32 CVE-2024-10775 Wordfence
6.5 Medium MT Addons for Elementor Plugin mt-addons-for-elementor Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-22811 Patchstack
6.4 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.1.7 CVE-2024-12328 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.4 CVE-2024-12205 Wordfence
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2024-56285 Patchstack
5.9 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2025-22316 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.31 Fixed in 2.4.32 CVE-2025-22333 Patchstack
4.3 Medium Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements Plugin ai-addons-for-elementor Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure ≤ 2.2.1 CVE-2024-12140 Wordfence
5.4 Medium Dragfy Addons for Elementor Plugin dragfy-addons-for-elementor Broken Access Control Broken Access Control + CSRF ≤ 1.0.2 CVE-2023-47661 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control Missing Authorization to Arbitrary Options Read ≤ 1.3.1 CVE-2024-12059 Wordfence
6.5 Medium Unlock Addons for Elementor Plugin unlock-addons-for-elementor Cross-Site Scripting ≤ 2.2.4 CVE-2024-54230 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-53796 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.14 Fixed in 6.0.1 CVE-2024-53823 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54212 Patchstack
4.3 Medium Gold Addons for Elementor Plugin gold-addons-for-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) License Activation/Deactivation ≤ 1.3.2 CVE-2024-12110 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.5.2 CVE-2024-8962 Wordfence
6.5 Medium Best Addons for Elementor Plugin best-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2024-53763 Patchstack
6.5 Medium Devnex Addons For Elementor Plugin devnex-addons-for-elementor Cross-Site Scripting ≤ 1.0.9 CVE-2024-53766 Patchstack
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.0.3 CVE-2024-10365 Wordfence
6.5 Medium Classy Addons for Elementor Plugin classy-addons-for-elementor Cross-Site Scripting ≤ 1.2.7 CVE-2024-50553 Patchstack
6.5 Medium Pro Addons For Elementor Plugin pro-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-51812 Patchstack
6.5 Medium Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51813 Patchstack
6.5 Medium Drozd – Addons for Elementor Plugin drozd-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-52425 Patchstack
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only