WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 151–190 of 190 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.4 High | SKT Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets |
≤ 2.0 |
CVE-2024-5091 |
Wordfence | |
| 8.8 High | PowerPack Pro for Elementor | Privilege Escalation Authenticated (Contributor+) Privilege Escalation |
≤ 2.10.17 |
CVE-2024-3668 |
Wordfence | |
| 7.2 High | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed |
≤ 2.0.6.1 |
CVE-2024-5542 |
Wordfence | |
| 7.5 High | Qi Addons For Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.7.2 |
CVE-2024-4887 |
Wordfence | |
| 8.8 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter |
≤ 1.5.109 |
CVE-2024-5329 |
Wordfence | |
| 8.8 High | Cowidgets – Elementor Addons | Local File Inclusion Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.1.2 |
CVE-2024-5179 |
Wordfence | |
| 8.8 High | Elements For Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Multiple Widget Attributes |
≤ 2.1 |
CVE-2024-5348 |
Wordfence | |
| 8.8 High | Responsive Owl Carousel for Elementor | Local File Inclusion |
≤ 1.2.0 |
CVE-2024-5345 |
Wordfence | |
| 8.8 High | Unlimited Elements for Elementor | Remote Code Execution Authenticated(Contributor+) Remote Code Execution via template import |
≤ 1.5.89 |
CVE-2023-6743 |
Wordfence | |
| 8.0 High | 140+ Widgets | Best Addons For Elementor – FREE | PHP Object Injection FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection |
≤ 1.4.3.1 |
CVE-2024-4471 |
Wordfence | |
| 8.8 High | Unlimited Elements for Elementor | SQL Injection Authenticated (Contributor+) SQL Injection via data[post_ids][0] |
≤ 1.5.107 |
CVE-2024-4779 |
Wordfence | |
| 8.5 High | Elementor Website Builder | Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization |
≤ 3.19.0 Fixed in 3.19.1 |
CVE-2024-24934 |
Patchstack | |
| 8.8 High | Ultimate Addons for Elementor | Privilege Escalation |
≤ 1.36.20 Fixed in 1.36.21 |
CVE-2023-50890 |
Patchstack | |
| 8.6 High | The Plus Addons for Elementor Pro | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 5.2.8 Fixed in 5.2.9 |
CVE-2023-47178 |
Patchstack | |
| 8.8 High | Essential Addons for Elementor | Privilege Escalation Contributor+ Privilege Escalation |
≤ 5.8.8 Fixed in 5.8.9 |
CVE-2023-41955 |
Patchstack | |
| 8.8 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 1.5.102 |
CVE-2024-3055 |
Wordfence | |
| 7.2 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Remote Code Execution Authenticated (Admin+) Command Injection |
≤ 1.5.102 |
CVE-2024-2662 |
Wordfence | |
| 7.2 High | EleForms – All In One Form Integration including DB for Elementor | Cross-Site Scripting All In One Form Integration including DB for Elementor <= 2.9.9.7 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.9.9.7 |
CVE-2024-2082 |
Wordfence | |
| 7.2 High | Database for Contact Form 7, WPforms, Elementor forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.3.8 |
CVE-2024-3715 |
Wordfence | |
| 8.2 High | Royal Elementor Addons and Templates | Arbitrary File Upload Unauthenticated Limited File Upload No login needed |
≤ 1.3.94 |
CVE-2024-1567 |
Wordfence | |
| 8.8 High | ElementsKit Elementor addons | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module |
≤ 3.1.0 |
CVE-2024-3499 |
Wordfence | |
| 7.5 High | HT Mega – Absolute Addons For Elementor | Information Disclosure Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products No login needed |
≤ 2.4.6 |
CVE-2023-6214 |
Wordfence | |
| 7.5 High | Piotnet Addons For Elementor Pro | Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed |
≤ 7.1.17 |
CVE-2024-33635 |
Patchstack | |
| 7.1 High | Piotnet Addons For Elementor Pro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 7.1.17 |
CVE-2024-33633 |
Patchstack | |
| 7.1 High | The Pack Elementor addons | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 2.0.8.3 Fixed in 2.0.8.4 |
CVE-2024-32785 |
Patchstack | |
| 7.1 High | Prime Slider – Addons For Elementor | Broken Access Control |
≤ 3.13.2 Fixed in 3.13.3 |
CVE-2024-32682 |
Patchstack | |
| 8.8 High | HT Mega – Absolute Addons For Elementor | Path Traversal Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal |
≤ 2.4.6 |
CVE-2024-1974 |
Wordfence | |
| 7.5 High | Layouts for Elementor | Arbitrary File Upload No login needed |
< 1.8 Fixed in 1.8 |
CVE-2024-30533 |
Patchstack | |
| 8.8 High | Essential Addons for Elementor | PHP Object Injection Authenticated (Author+) PHP Object Injection via error_resetpassword |
≤ 5.9.13 |
CVE-2024-3018 |
Wordfence | |
| 8.8 High | ElementsKit Elementor addons | Local File Inclusion Authenticated (Contributor+) Local File Inclusion in render_raw |
≤ 3.0.6 |
CVE-2024-2047 |
Wordfence | |
| 8.5 High | Element Pack Elementor Addons | SQL Injection |
≤ 5.5.3 Fixed in 5.5.4 |
CVE-2024-30496 |
Patchstack | |
| 7.1 High | Starter Templates — Elementor, WordPress & Beaver Builder Templates | Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins |
≤ 3.2.4 Fixed in 3.2.5 |
CVE-2023-34370 |
Patchstack | |
| 7.1 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.5.93 Fixed in 1.5.94 |
CVE-2024-29792 |
Patchstack | |
| 8.8 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup |
≤ 1.6.7 |
CVE-2024-2006 |
Wordfence | |
| 8.8 High | Elementor Addon Elements | Path Traversal Directory Traversal to Local File Inclusion |
≤ 1.12.12 |
CVE-2024-1358 |
Wordfence | |
| 7.4 High | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar |
≤ 5.9.9 |
CVE-2024-1536 |
Wordfence | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 7.1 High | Mighty Addons for Elementor | Cross-Site Scripting WordPress Mighty Addons for Elementor Plugin <= 1.9.3 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 1.9.3 |
CVE-2024-24846 |
Patchstack | |
| 7.5 High | Royal Elementor Addons and Templates | Broken Access Control Unauthenticated Arbitrary Post Read No login needed |
< 1.3.81 Fixed in 1.3.81 |
CVE-2023-5922 |
WPScan | |
| 8.8 High | Dynamic Content for Elementor | Cross-Site Request Forgery WordPress Dynamic Content for Elementor Plugin < 2.12.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.12.5 Fixed in 2.12.5 |
CVE-2023-52150 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.