WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,451–1,500 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL ≤ 1.0.16 CVE-2024-2507 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Carousel Widget ≤ 8.3.4 CVE-2024-1465 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget ≤ 8.3.4 CVE-2024-1464 Wordfence
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure No login needed ≤ 5.9.13 CVE-2024-2974 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.14 CVE-2024-3244 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag ≤ 3.10.4 CVE-2024-2788 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.11 CVE-2024-2650 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget ≤ 8.3.4 CVE-2024-1466 Wordfence
5.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag ≤ 3.10.4 CVE-2024-2786 Wordfence
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2024-0826 Wordfence
6.4 Medium BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg Plugin Cross-Site Scripting Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.4.2 CVE-2024-2845 Wordfence
6.4 Medium Elementor Addons, Widgets and Enhancements – Stax Plugin stax-addons-for-elementor Cross-Site Scripting Stax <= 1.4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.4.1 CVE-2024-3064 Wordfence
8.8 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Path Traversal Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.6 CVE-2024-1974 Wordfence
6.4 Medium PowerPack Addons for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Tweet Widget ≤ 2.7.18 CVE-2024-2492 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Wrapper Link Widget ≤ 4.10.16 CVE-2024-0376 Wordfence
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.5.2 Fixed in 1.6.0 CVE-2024-31357 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-31236 Patchstack
6.5 Medium Gradient Text Widget for Elementor Plugin gradient-text-widget-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-31346 Patchstack
6.4 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Widget ≤ 1.4.0 CVE-2024-2132 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block ≤ 3.9.14 CVE-2024-3245 Wordfence
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.0.7 CVE-2024-2803 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout ≤ 2.8.3 CVE-2024-2868 Wordfence
6.4 Medium Jeg Elementor Kit Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial ≤ 2.6.3 CVE-2024-3162 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box ≤ 2.6.3 CVE-2024-1327 Wordfence
6.4 Medium Creative Addons for Elementor Plugin creative-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.12 CVE-2024-2924 Wordfence
6.4 Medium Metform Elementor Contact Form Builder Plugin metform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widgets ≤ 3.8.5 CVE-2024-2791 Wordfence
6.5 Medium PDF Viewer for Elementor Plugin pdf-viewer-for-elementor Cross-Site Scripting ≤ 2.9.3 CVE-2024-30524 Patchstack
7.5 High Layouts for Elementor Plugin layouts-for-elementor Arbitrary File Upload No login needed < 1.8 Fixed in 1.8 CVE-2024-30533 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite PHP Object Injection Authenticated (Author+) PHP Object Injection via error_resetpassword ≤ 5.9.13 CVE-2024-3018 Wordfence
6.4 Medium PowerPack Addons for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via *_html_tag* ≤ 2.7.17 CVE-2024-2491 Wordfence
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.0.6 CVE-2024-1238 Wordfence
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Link ≤ 1.5.96 CVE-2024-0367 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion in render_raw ≤ 3.0.6 CVE-2024-2047 Wordfence
8.5 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30496 Patchstack
6.5 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-30423 Patchstack
6.4 Medium 130+ Widgets | Best Addons For Elementor – FREE Plugin Cross-Site Scripting FREE <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.2 CVE-2024-2250 Wordfence
6.4 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via widget links ≤ 1.4.1 CVE-2024-2280 Wordfence
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting ≤ 1.13.1 Fixed in 1.13.2 CVE-2024-30422 Patchstack
7.1 High Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-34370 Patchstack
5.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.13.2 CVE-2024-2091 Wordfence
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.93 Fixed in 1.5.94 CVE-2024-29792 Patchstack
6.5 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting ≤ 3.13.1 Fixed in 3.13.2 CVE-2024-30186 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30185 Patchstack
6.5 Medium HT Mega Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor plugin <= 2.4.3 - Cross Site Scripting (XSS) ≤ 2.4.3 Fixed in 2.4.4 CVE-2024-30182 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.8 Fixed in 2.6.9 CVE-2024-30177 Patchstack
6.5 Medium Image Hover Effects – Elementor Addon Plugin image-hover-effects-addon-for-elementor Cross-Site Scripting Elementor Addon plugin <= 1.4 - Cross Site Scripting (XSS) ≤ 1.4 Fixed in 1.4.1 CVE-2024-29936 Patchstack
6.5 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting ≤ 3.5.0 Fixed in 3.5.1 CVE-2024-29935 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.25 Fixed in 2.4.26 CVE-2024-29934 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only