WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–190 of 190 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.4 High SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets ≤ 2.0 CVE-2024-5091 Wordfence
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 2.10.17 CVE-2024-3668 Wordfence
7.2 High Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed ≤ 2.0.6.1 CVE-2024-5542 Wordfence
7.5 High Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.7.2 CVE-2024-4887 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter ≤ 1.5.109 CVE-2024-5329 Wordfence
8.8 High Cowidgets – Elementor Addons Plugin Local File Inclusion Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion ≤ 1.1.2 CVE-2024-5179 Wordfence
8.8 High Elements For Elementor Plugin nd-elements Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Multiple Widget Attributes ≤ 2.1 CVE-2024-5348 Wordfence
8.8 High Responsive Owl Carousel for Elementor Plugin responsive-owl-carousel-elementor Local File Inclusion ≤ 1.2.0 CVE-2024-5345 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated(Contributor+) Remote Code Execution via template import ≤ 1.5.89 CVE-2023-6743 Wordfence
8.0 High 140+ Widgets | Best Addons For Elementor – FREE Plugin xpro-elementor-addons PHP Object Injection FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection ≤ 1.4.3.1 CVE-2024-4471 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via data[post_ids][0] ≤ 1.5.107 CVE-2024-4779 Wordfence
8.5 High Elementor Website Builder Plugin elementor Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization ≤ 3.19.0 Fixed in 3.19.1 CVE-2024-24934 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.20 Fixed in 1.36.21 CVE-2023-50890 Patchstack
8.6 High The Plus Addons for Elementor Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.2.8 Fixed in 5.2.9 CVE-2023-47178 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Contributor+ Privilege Escalation ≤ 5.8.8 Fixed in 5.8.9 CVE-2023-41955 Patchstack
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.5.102 CVE-2024-3055 Wordfence
7.2 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated (Admin+) Command Injection ≤ 1.5.102 CVE-2024-2662 Wordfence
7.2 High EleForms – All In One Form Integration including DB for Elementor Plugin Cross-Site Scripting All In One Form Integration including DB for Elementor <= 2.9.9.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.9.9.7 CVE-2024-2082 Wordfence
7.2 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.8 CVE-2024-3715 Wordfence
8.2 High Royal Elementor Addons and Templates Plugin royal-elementor-addons Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.3.94 CVE-2024-1567 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module ≤ 3.1.0 CVE-2024-3499 Wordfence
7.5 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Information Disclosure Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products No login needed ≤ 2.4.6 CVE-2023-6214 Wordfence
7.5 High Piotnet Addons For Elementor Pro Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 7.1.17 CVE-2024-33635 Patchstack
7.1 High Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.17 CVE-2024-33633 Patchstack
7.1 High The Pack Elementor addons Plugin the-pack-addon Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 2.0.8.3 Fixed in 2.0.8.4 CVE-2024-32785 Patchstack
7.1 High Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32682 Patchstack
8.8 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Path Traversal Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.6 CVE-2024-1974 Wordfence
7.5 High Layouts for Elementor Plugin layouts-for-elementor Arbitrary File Upload No login needed < 1.8 Fixed in 1.8 CVE-2024-30533 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite PHP Object Injection Authenticated (Author+) PHP Object Injection via error_resetpassword ≤ 5.9.13 CVE-2024-3018 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion in render_raw ≤ 3.0.6 CVE-2024-2047 Wordfence
8.5 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30496 Patchstack
7.1 High Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-34370 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.93 Fixed in 1.5.94 CVE-2024-29792 Patchstack
8.8 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup ≤ 1.6.7 CVE-2024-2006 Wordfence
8.8 High Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Path Traversal Directory Traversal to Local File Inclusion ≤ 1.12.12 CVE-2024-1358 Wordfence
7.4 High Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar ≤ 5.9.9 CVE-2024-1536 Wordfence
7.1 High PowerPack Pro for Elementor Plugin Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed < 2.10.8 Fixed in 2.10.8 CVE-2024-24843 Patchstack
7.1 High Mighty Addons for Elementor Plugin mighty-addons Cross-Site Scripting WordPress Mighty Addons for Elementor Plugin <= 1.9.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.9.3 CVE-2024-24846 Patchstack
7.5 High Royal Elementor Addons and Templates Plugin Broken Access Control Unauthenticated Arbitrary Post Read No login needed < 1.3.81 Fixed in 1.3.81 CVE-2023-5922 WPScan
8.8 High Dynamic Content for Elementor Plugin Cross-Site Request Forgery WordPress Dynamic Content for Elementor Plugin < 2.12.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed < 2.12.5 Fixed in 2.12.5 CVE-2023-52150 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only