WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Broken Access Control Missing Authorization to Unauthenticated Form Action Meta Modification No login needed ≤ 1.7.1056 CVE-2026-4024 Wordfence
6.4 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_content_number_prefix' Shortcode Attribute ≤ 3.1.0 CVE-2026-6916 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 4.0.4 CVE-2026-6127 Wordfence
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-42410 Patchstack
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field ≤ 1.7.1056 CVE-2026-5428 Wordfence
6.4 Medium Flipbox Addon for Elementor Plugin ultimate-flipbox-addon-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Attributes ≤ 2.0.8 CVE-2026-6048 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget ≤ 1.7.1056 CVE-2026-5162 Wordfence
6.4 Medium Livemesh Addons by Elementor Plugin addons-for-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings ≤ 9.0 CVE-2026-1572 Wordfence
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed ≤ 1.7.1056 Fixed in 1.7.1057 CVE-2026-40763 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.8.1 CVE-2026-39703 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Cross-Site Scripting ≤ 2.6.1 CVE-2026-39702 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Cross-Site Scripting ≤ 9.0 CVE-2026-39636 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-39500 Patchstack
6.4 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget ≤ 8.4.2 CVE-2026-4655 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 3.35.5 CVE-2025-14732 Wordfence
6.4 Medium Xpro Addons — 140+ Widgets for Elementor Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.20 CVE-2025-13368 Wordfence
6.4 Medium ElementsKit Elementor Addons and Templates Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget ≤ 3.7.9 CVE-2026-2600 Wordfence
6.4 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass ≤ 1.7.1049 CVE-2026-0664 Wordfence
6.4 Medium Xpro Addons — 140+ Widgets for Elementor Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget ≤ 1.4.24 CVE-2026-2949 Wordfence
6.4 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets ≤ 51.1.53 CVE-2025-13535 Wordfence
4.3 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 1.4.9 CVE-2026-3831 Wordfence
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 3.35.7 CVE-2026-1206 Wordfence
6.5 Medium WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly Broken Access Control ≤ <= 1.1.5 Fixed in 1.1.6 CVE-2026-32527 Patchstack
6.5 Medium Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-mailchimp Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-25430 Patchstack
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control ≤ 1.6.4 Fixed in 1.7.0 CVE-2026-25398 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Information Disclosure Unauthenticated API Keys Disclosure No login needed ≤ 51.1.49 CVE-2025-13997 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `Fancy Text Widget` And `Countdown Widget` ≤ 3.7.0 CVE-2025-6229 Wordfence
6.4 Medium PQ Addons – Creative Elementor Widgets Plugin peacefulqode-elementzplus-widgets Cross-Site Scripting Creative Elementor Widgets <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Attributes ≤ 1.0.0 CVE-2026-1397 Wordfence
5.3 Medium Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin royal-elementor-addons Broken Access Control Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure No login needed ≤ 1.7.1049 CVE-2026-2373 Wordfence
5.3 Medium Thim Kit for Elementor Plugin thim-elementor-kit Broken Access Control Missing Authorization to Unauthenticated Private Course Disclosure No login needed ≤ 1.3.7 CVE-2026-1870 Wordfence
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2026-32462 Patchstack
6.5 Medium PowerPack Addons for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting ≤ 2.9.9 Fixed in 2.9.10 CVE-2026-32430 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-32429 Patchstack
5.3 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Broken Access Control Lite plugin <= 1.5.6 - Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2026-32395 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
5.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter ≤ 3.21.0 CVE-2026-2917 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions ≤ 3.21.0 CVE-2026-2918 Wordfence
6.1 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'themebuilder' Parameter No login needed ≤ 1.6.8 CVE-2025-12473 Wordfence
6.4 Medium OoohBoi Steroids for Elementor Plugin ooohboi-steroids-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls ≤ 2.1.24 CVE-2026-3034 Wordfence
6.4 Medium Xpro Addons — 140+ Widgets for Elementor Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link ≤ 1.4.24 CVE-2025-14149 Wordfence
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2024-52387 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.29.0 Fixed in 3.29.1 CVE-2024-50555 Patchstack
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' ≤ 2.1.1 CVE-2026-2486 Wordfence
4.3 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.4.2 CVE-2026-25416 Patchstack
4.3 Medium Image Optimizer by Elementor Plugin image-optimization Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-25387 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only