WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 1,359 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Gmaper for Elementor Plugin gmaper-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66158 Patchstack
5.4 Medium Walker for Elementor Plugin walker-elementor Broken Access Control ≤ 1.1.6 CVE-2025-66159 Patchstack
5.4 Medium Select Graphist for Elementor Graphist for Elementor Plugin graphist-elementor Broken Access Control ≤ 1.2.10 CVE-2025-66160 Patchstack
5.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2025-63053 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.5.3 Fixed in 6.5.4 CVE-2025-69092 Patchstack
5.3 Medium HomeFix Elementor Portfolio Plugin homefix-ele-portfolio Broken Access Control No login needed ≤ 1.0.1 CVE-2025-68981 Patchstack
5.4 Medium Better Elementor Addons Plugin better-elementor-addons Broken Access Control ≤ 1.3.7 Fixed in 1.3.9 CVE-2023-41656 Patchstack
5.4 Medium TheGem (Elementor) Theme thegem-elementor Broken Access Control < 5.8.1.1 Fixed in 5.8.1.1 CVE-2023-32238 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control No login needed ≤ 2.0.5.3 Fixed in 2.0.5.4.1 CVE-2023-40679 Patchstack
6.5 Medium ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68532 Patchstack
4.9 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) ≤ 4.0.10 Fixed in 4.1.0 CVE-2025-68500 Patchstack
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.11.53 Fixed in 4.11.54 CVE-2025-68494 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68559 Patchstack
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.20.3 CVE-2025-14635 Wordfence
4.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Request Forgery Cross-Site Request Forgery via 'insert_inner_template' No login needed ≤ 4.11.53 CVE-2025-14163 Wordfence
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content' No login needed ≤ 4.11.53 CVE-2025-14155 Wordfence
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0.1.2 CVE-2025-62094 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12 Fixed in 2.7.12.1 CVE-2025-64355 Patchstack
4.3 Medium Prime Slider – Addons for Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 4.0.9 CVE-2025-14277 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.5.3 CVE-2025-13977 Wordfence
6.4 Medium Elementor Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path ≤ 3.33.3 CVE-2025-11220 Wordfence
5.4 Medium Huger for Elementor Plugin huger-elementor Broken Access Control ≤ 1.1.5 CVE-2025-68088 Patchstack
5.4 Medium Modalier for Elementor Plugin modalier-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68087 Patchstack
5.4 Medium Reformer for Elementor Plugin reformer-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68086 Patchstack
5.4 Medium Buttoner for Elementor Plugin buttoner-elementor Broken Access Control Settings Change ≤ 1.0.6 CVE-2025-68085 Patchstack
6.5 Medium WPZOOM Addons for Elementor Plugin wpzoom-elementor-addons Cross-Site Scripting ≤ 1.2.10 Fixed in 1.2.11 CVE-2025-67951 Patchstack
5.4 Medium Lottier for Elementor Plugin lottier-elementor Broken Access Control ≤ 1.0.9 CVE-2025-66166 Patchstack
5.4 Medium Masker for Elementor Plugin masker-elementor Broken Access Control ≤ 1.1.4 CVE-2025-66163 Patchstack
5.4 Medium Spoter for Elementor Plugin spoter-elementor Broken Access Control ≤ 1.04 CVE-2025-66162 Patchstack
5.4 Medium Grider for Elementor Plugin grider-elementor Broken Access Control ≤ 1.0.8 CVE-2025-66161 Patchstack
5.4 Medium Coder for Elementor Plugin coder-elementor Broken Access Control ≤ 1.0.13 CVE-2025-66147 Patchstack
4.3 Medium Restrict Elementor Widgets, Columns and Sections Plugin restrict-elementor-widgets Broken Access Control ≤ 1.12 CVE-2025-64244 Patchstack
5.3 Medium Royal Elementor Addons and Templates Plugin Arbitrary File Upload Unauthenticated Media File Upload No login needed < 1.7.1037 Fixed in 1.7.1037 CVE-2025-11363 WPScan
6.4 Medium Addon Elements for Elementor Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.14.3 CVE-2025-12537 Wordfence
6.4 Medium MarqueeAddons Plugin marquee-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget ≤ 2.4.3 CVE-2025-8199 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets ≤ 1.0.20 CVE-2025-8195 Wordfence
6.4 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 51.1.39 CVE-2025-7960 Wordfence
6.4 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team and Countdown Widgets ≤ 2.5.6 CVE-2025-8779 Wordfence
6.4 Medium HT Slider for Elementor Plugin ht-slider-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.4 CVE-2025-14278 Wordfence
6.4 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Widget ≤ 1.5.5 CVE-2025-12830 Wordfence
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control ≤ 3.20.3 Fixed in 3.20.4 CVE-2025-63077 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2025-63055 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.19.1 Fixed in 1.4.20 CVE-2025-63044 Patchstack
6.5 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-63042 Patchstack
5.9 Medium Make Section & Column Clickable For Elementor Plugin make-section-column-clickable-elementor Cross-Site Scripting ≤ 2.4 Fixed in 2.4.1 CVE-2025-63033 Patchstack
6.5 Medium Generic Elements Plugin generic-elements-for-elementor Cross-Site Scripting ≤ 1.2.9 CVE-2025-62082 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-67594 Patchstack
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.33.0 Fixed in 3.33.1 CVE-2025-67588 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Broken Access Control Arbitrary Content Deletion ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-67540 Patchstack
4.3 Medium Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-67468 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only