WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control Unauthenticated Open Registration No login needed < 1.6.1 Fixed in 1.6.1 CVE-2026-12276 WPScan
6.4 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget ≤ 2.6.3 CVE-2026-15299 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 6.4.11 CVE-2026-15285 Wordfence
6.4 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter ≤ 51.1.62 CVE-2026-15284 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup ≤ 6.6.2 CVE-2026-6459 Wordfence
6.4 Medium Sympl Repeater for ACF and Elementor Plugin acf-repeater-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values ≤ 2.3 CVE-2026-10570 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 2.7.9.8 CVE-2026-11328 Wordfence
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.9.9 Fixed in 2.8.0 CVE-2026-59511 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Local File Inclusion Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter ≤ 2.0.7 CVE-2026-5137 Wordfence
6.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter ≤ 2.0.7 CVE-2026-8351 Wordfence
6.5 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Path Traversal Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' No login needed ≤ 1.5.1 CVE-2026-9145 Wordfence
4.3 Medium Envo's Templates & Widgets for Elementor and WooCommerce Plugin envo-elementor-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting ≤ 1.4.26 CVE-2026-11600 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting ≤ 1.0.21 CVE-2026-11380 Wordfence
9.8 Critical Easy Elements for Elementor – Addons & Website Templates Plugin easy-elements Privilege Escalation Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation No login needed ≤ 1.4.9 Fixed in 1.5.0 CVE-2026-56028 Patchstack
4.3 Medium Live Copy Paste for Elementor Plugin live-copy-paste Broken Access Control ≤ 1.5.3 CVE-2025-63079 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.7.9.8 Fixed in 2.7.9.9 CVE-2026-57620 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Information Disclosure Sensitive Data Exposure ≤ 4.1.3 Fixed in 4.1.4 CVE-2026-57619 Patchstack
6.4 Medium Xpro Addons Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets ≤ 1.7.2 CVE-2026-11614 Wordfence
8.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed ≤ 1.5.1 CVE-2026-9843 Wordfence
6.5 Medium Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin royal-elementor-addons Path Traversal Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source 1.7.1058 – 1.7.1059 CVE-2026-8118 Wordfence
7.1 High Royal Elementor Addons Pro Plugin wpr-addons-pro Cross-Site Scripting No login needed < 1.7.1041 Fixed in 1.7.1041 CVE-2026-40720 Patchstack
8.8 High PowerPack Pro for Elementor Plugin powerpack-elements Authentication Bypass Broken Authentication No login needed < v2.13.0 Fixed in 2.13.0 CVE-2026-42629 Patchstack
7.1 High WPZOOM Addons for Elementor Plugin wpzoom-elementor-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-39597 Patchstack
9.9 Critical Unlimited Elements for Elementor (Premium) Plugin unlimited-elements-for-elementor-premium Arbitrary File Upload ≤ 2.0.6 CVE-2026-27041 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter ≤ 2.0.7 CVE-2026-5149 Wordfence
9.8 Critical Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp PHP Object Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2026-49765 Patchstack
9.8 Critical Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-49109 Patchstack
9.8 Critical WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49105 Patchstack
9.8 Critical Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-infusionsoft PHP Object Injection No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2026-49104 Patchstack
9.8 Critical WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly PHP Object Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-49085 Patchstack
6.5 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting ≤ 51.1.62 Fixed in 51.1.63 CVE-2026-48870 Patchstack
7.1 High Product Filter Widget for Elementor Plugin product-filter-widget-for-elementor Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2026-45437 Patchstack
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control No login needed < 6.6.0 Fixed in 6.6.0 CVE-2026-25440 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
5.4 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Broken Access Control No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2023-25969 Patchstack
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting ≤ 1.1.8 CVE-2026-8613 Wordfence
6.4 Medium Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates Plugin animation-addons-for-elementor Cross-Site Scripting GSAP Powered Elementor Addons & Website Templates <= 2.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters ≤ 2.6.7 CVE-2025-8444 Wordfence
6.4 Medium Prime Elementor Addons Plugin unlimited-elementor-inner-sections-by-boomdevs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget HTML Tag Settings ≤ 1.3.3 CVE-2026-8677 Wordfence
6.1 Medium Product Filter Widget for Elementor Plugin product-filter-widget-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter No login needed ≤ 1.0.6 CVE-2026-11603 Wordfence
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler No login needed ≤ 6.6.4 CVE-2026-7665 Wordfence
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) ≤ 3.1.0 CVE-2026-9281 Wordfence
5.4 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2026-49782 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter ≤ 6.4.15 CVE-2026-9243 Wordfence
5.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control No login needed ≤ 3.9.6 CVE-2026-49053 Patchstack
4.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control ≤ 3.9.6 CVE-2026-49052 Patchstack
6.5 Medium Xpro Elementor Addons - Pro Plugin Path Traversal Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG ≤ 1.4.7 CVE-2025-0898 Wordfence
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
6.4 Medium Style Kits – Advanced Theme Styles for Elementor Plugin analogwp-templates Cross-Site Scripting Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Kit Title ≤ 2.5.0 CVE-2026-6565 Wordfence
8.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-48837 Patchstack
8.8 High Easy Elements for Elementor – Addons & Website Templates Plugin easy-elements Privilege Escalation Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter ≤ 1.4.5 CVE-2026-9018 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only