WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 190 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Animation Addons for Elementor Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.6 CVE-2025-1639 Wordfence
8.8 High Templines Elementor Helper Core Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.7 CVE-2025-1295 Wordfence
8.8 High Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Local File Inclusion Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.4 CVE-2024-13353 Wordfence
7.2 High Lenix Elementor Leads addon Plugin lenix-elementor-leads-addon Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via URL Form Field No login needed ≤ 1.8.2 CVE-2025-1039 Wordfence
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Arbitrary File Read No login needed ≤ 1.7.5 Fixed in 2.0.1 CVE-2025-24569 Patchstack
7.2 High Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Remote Code Execution Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.0 - Authenticated (Administrator+) Remote Code Execution ≤ 1.6.0 CVE-2024-11600 Wordfence
7.1 High WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-dynamics-crm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24708 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
7.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Local File Inclusion ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-22786 Patchstack
7.5 High WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Local File Inclusion ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56282 Patchstack
7.1 High Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56226 Patchstack
8.8 High WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Plugin wte-elementor-widgets Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion ≤ 1.3.7 CVE-2024-12272 Wordfence
8.1 High Cryptocurrency Widgets For Elementor Plugin cryptocurrency-widgets-for-elementor Local File Inclusion No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-53739 Patchstack
7.5 High Absolute Addons For Elementor Plugin absolute-addons Local File Inclusion ≤ 1.0.14 CVE-2024-52496 Patchstack
7.5 High Shopready Plugin shopready-elementor-addon Local File Inclusion ≤ 3.6 CVE-2024-52497 Patchstack
7.5 High Pricing table addon for elementor Plugin pricing-table-addon-for-elementor Local File Inclusion ≤ 1.0.0 CVE-2024-52499 Patchstack
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
8.8 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.4.2 CVE-2024-10873 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
7.1 High Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.37 CVE-2024-52471 Patchstack
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 2.0.0 CVE-2024-9935 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
7.1 High Extra Privacy for Elementor Plugin extra-privacy-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2024-49654 Patchstack
7.5 High The Pack Elementor addons Plugin the-pack-addon Local File Inclusion ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-50453 Patchstack
7.5 High Dynamic Elementor Addons Plugin dynamic-elementor-addons Local File Inclusion ≤ 1.0.0 CVE-2024-49243 Patchstack
7.1 High EasyJobs Plugin easyjobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-43997 Patchstack
7.5 High Maan Addons For Elementor Plugin maan-elementor-addons Local File Inclusion ≤ 1.0.1 CVE-2024-49251 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 4.6.4 CVE-2021-4447 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-45454 Patchstack
7.1 High SKT Templates – Elementor & Gutenberg templates Plugin skt-templates Cross-Site Scripting Elementor & Gutenberg templates plugin <= 6.14 - Reflected Cross Site Scripting (XSS) No login needed ≤ 6.14 Fixed in 6.15 CVE-2024-44007 Patchstack
8.5 High Woo Products Widgets For Elementor Plugin woo-products-widgets-for-elementor Local File Inclusion ≤ 2.0.0 CVE-2024-43271 Patchstack
8.1 High Metform Elementor Contact Form Builder Plugin metform Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed ≤ 3.2.4 CVE-2023-0714 Wordfence
7.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-43140 Patchstack
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.10.14 Fixed in 2.10.15 CVE-2024-39634 Patchstack
8.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-37462 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.31 Fixed in 1.36.32 CVE-2024-37455 Patchstack
7.5 High Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Local File Inclusion Elementor Addons plugin <= 1.1.1 - Local File Inclusion No login needed ≤ 1.1.1 Fixed in 1.2.0 CVE-2024-37419 Patchstack
8.5 High Masterstudy Elementor Widgets Theme SQL Injection SQL Injection vulnerability in multiple StylemixThemes premium themes ≤ 1.2.2, ≤ 1.3.0 Fixed in 1.2.3 CVE-2024-37090 Patchstack
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Time-Based SQL Injection ≤ 1.5.112 CVE-2024-6166 Wordfence
8.8 High Elementor Addons by Livemesh Plugin addons-for-elementor Local File Inclusion Authenticated (Contributor+) Limited Local File Inclusion via Widgets ≤ 8.4 CVE-2024-2385 Wordfence
8.5 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Contributor+ Local File Inclusion ≤ 1.3.8.1 Fixed in 1.3.9 CVE-2024-37479 Patchstack
8.8 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.3.8.1 CVE-2024-5349 Wordfence
8.5 High Consulting Elementor Widgets Plugin Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37092 Patchstack
8.8 High The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Local File Inclusion Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion ≤ 5.5.6 CVE-2024-5455 Wordfence
7.5 High JetElements For Elementor Plugin Broken Access Control Unauthenticated Arbitrary Attachment Download No login needed ≤ 2.6.13 Fixed in 2.6.13.1 CVE-2023-48759 Patchstack
8.2 High JetElements For Elementor Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.6.13 Fixed in 2.6.13.1 CVE-2023-48760 Patchstack
8.3 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control Multiple Broken Access Control ≤ 1.5.65 Fixed in 1.5.66 CVE-2023-31080 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only