WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–25 of 25 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
5.3 Medium Post Carousel Plugin Information Disclosure Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id No login needed 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78149 WPScan
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
6.4 Medium Multi Post Carousel by Category Plugin multi-post-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slides' Shortcode Attribute ≤ 1.4 CVE-2026-1275 Wordfence
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control ≤ 1.7.0 CVE-2025-57955 Patchstack
4.3 Medium Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid Plugin blog-designer-for-elementor Cross-Site Request Forgery Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-8481 Wordfence
4.3 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function ≤ 1.6.0 CVE-2025-3863 Wordfence
4.8 Medium Custom Post Carousels with Owl Plugin dd-post-carousel Cross-Site Scripting Contributor+ Stored XSS < 1.4.12 Fixed in 1.4.12 CVE-2025-5125 WPScan
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
3.5 Low Post Grid, Post Carousel, & List Category Posts Plugin Cross-Site Scripting Editor+ Stored XSS < 2.4.28 Fixed in 2.4.28 CVE-2024-3996 WPScan
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
7.1 High Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-22750 Patchstack
6.4 Medium Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11770 Wordfence
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget ≤ 2.2.85 CVE-2024-6346 Wordfence
6.4 Medium Ultimate Post Kit Addons for Elementor Plugin ultimate-post-kit Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget ≤ 3.11.7 CVE-2024-5662 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute ≤ 2.2.80 CVE-2024-4042 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-1988 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-3155 Wordfence
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence
6.4 Medium Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' ≤ 2.6.3 CVE-2024-2949 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Carousel Widget ≤ 2.4.4 CVE-2024-1421 Wordfence
6.5 Medium Custom Post Carousels with Owl Plugin dd-post-carousel Cross-Site Scripting WordPress Custom Post Carousels with Owl Plugin <= 1.4.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-51493 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only