WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 1,616 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control ≤ 1.6.4 Fixed in 1.7.0 CVE-2026-25398 Patchstack
8.5 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-25007 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Information Disclosure Unauthenticated API Keys Disclosure No login needed ≤ 51.1.49 CVE-2025-13997 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `Fancy Text Widget` And `Countdown Widget` ≤ 3.7.0 CVE-2025-6229 Wordfence
6.4 Medium PQ Addons – Creative Elementor Widgets Plugin peacefulqode-elementzplus-widgets Cross-Site Scripting Creative Elementor Widgets <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Attributes ≤ 1.0.0 CVE-2026-1397 Wordfence
5.3 Medium Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin royal-elementor-addons Broken Access Control Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure No login needed ≤ 1.7.1049 CVE-2026-2373 Wordfence
5.3 Medium Thim Kit for Elementor Plugin thim-elementor-kit Broken Access Control Missing Authorization to Unauthenticated Private Course Disclosure No login needed ≤ 1.3.7 CVE-2026-1870 Wordfence
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2026-32462 Patchstack
2.7 Low Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32445 Patchstack
6.5 Medium PowerPack Addons for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting ≤ 2.9.9 Fixed in 2.9.10 CVE-2026-32430 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-32429 Patchstack
5.3 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Broken Access Control Lite plugin <= 1.5.6 - Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2026-32395 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
5.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter ≤ 3.21.0 CVE-2026-2917 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions ≤ 3.21.0 CVE-2026-2918 Wordfence
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass ≤ 1.7.1049 CVE-2025-13067 Wordfence
6.1 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'themebuilder' Parameter No login needed ≤ 1.6.8 CVE-2025-12473 Wordfence
7.2 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Entry Fields No login needed ≤ 2.0.5 CVE-2026-2724 Wordfence
9.8 Critical Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via 'download_csv' No login needed ≤ 1.4.7 CVE-2026-2599 Wordfence
8.2 High Royal Elementor Addons Plugin royal-elementor-addons Other Other vulnerability Type No login needed ≤ 1.7.1052 Fixed in 1.7.1053 CVE-2026-28135 Patchstack
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
6.4 Medium OoohBoi Steroids for Elementor Plugin ooohboi-steroids-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls ≤ 2.1.24 CVE-2026-3034 Wordfence
7.2 High WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-zendesk Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1.5 CVE-2026-2568 Wordfence
8.8 High Master Addons for Elementor Premium Plugin master-addons Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via render_preview ≤ 2.1.3 CVE-2026-3132 Wordfence
6.4 Medium Xpro Addons — 140+ Widgets for Elementor Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link ≤ 1.4.24 CVE-2025-14149 Wordfence
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
10.0 Critical ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor Plugin elementskit-lite Broken Access Control ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint No login needed < 3.7.9 Fixed in 3.7.9 CVE-2026-23693 VulnCheck
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
9.3 Critical Download Manager Addons for Elementor Plugin wpdm-elementor SQL Injection No login needed ≤ 1.3.0 Fixed in 2.0.0 CVE-2026-24956 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
9.8 Critical Themesflat Elementor Plugin themesflat-elementor PHP Object Injection No login needed ≤ 1.0.1 CVE-2025-69382 Patchstack
8.1 High Eleblog – Elementor Blog And Magazine Addons Plugin ele-blog Local File Inclusion Elementor Blog And Magazine Addons plugin <= 2.0.3 - Local File Inclusion No login needed ≤ 2.0.3 CVE-2025-69374 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
8.8 High ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery PHP Object Injection ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68531 Patchstack
8.8 High Miraculous Elementor Plugin miraculous-el Authentication Bypass Broken Authentication ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-67998 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.9.9.4 Fixed in 2.1.0 CVE-2024-52387 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.29.0 Fixed in 3.29.1 CVE-2024-50555 Patchstack
6.4 Medium Master Addons For Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' ≤ 2.1.1 CVE-2026-2486 Wordfence
4.3 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.4.2 CVE-2026-25416 Patchstack
4.3 Medium Image Optimizer by Elementor Plugin image-optimization Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-25387 Patchstack
5.3 Medium Elementor Contact Form DB Plugin sb-elementor-contact-form-db Broken Access Control No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2026-25320 Patchstack
4.3 Medium Zita Elementor Site Library Plugin zita-site-library Cross-Site Request Forgery No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-25319 Patchstack
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control No login needed ≤ 6.5.5 Fixed in 6.5.6 CVE-2026-23543 Patchstack
5.4 Medium News Element Elementor Blog Magazine Plugin news-element Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Loss ≤ 1.0.8 CVE-2026-2284 Wordfence
4.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' ≤ 6.4.7 CVE-2026-2386 Wordfence
6.5 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 8.3.17 CVE-2026-1793 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget ≤ 6.5.9 CVE-2026-1512 Wordfence
5.3 Medium WPZOOM Addons for Elementor – Starter Templates & Widgets Plugin wpzoom-elementor-addons Broken Access Control Starter Templates & Widgets <= 1.3.2 - Unauthenticated Protected Post Exposure via ajax_post_grid_load_more No login needed ≤ 1.3.2 CVE-2026-2295 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only