WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 1–50 of 164 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium EmbedPress Plugin embedpress Cross-Site Scripting Contributor+ Stored XSS via Instagram Carousel Block Attributes < 4.6.7 Fixed in 4.6.7 CVE-2026-85002 WPScan
2.7 Low Post Carousel Plugin Information Disclosure Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78150 WPScan
5.3 Medium Post Carousel Plugin Information Disclosure Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id No login needed 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78149 WPScan
6.8 Medium Post Grid, Slider & Carousel Ultimate Plugin Cross-Site Scripting Contributor+ Stored XSS via Header Title Field < 1.8.1 Fixed in 1.8.1 CVE-2026-16260 WPScan
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting ≤ 3.111.0 CVE-2026-18400 Wordfence
5.9 Medium Custom links in Elementor Image Carousel Plugin custom-links-in-elementor-image-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2026-65534 Patchstack
6.5 Medium Image Carousel Plugin image-carousel Cross-Site Scripting ≤ 1.0.0.41 CVE-2025-68074 Patchstack
6.4 Medium Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter ≤ 3.1.31 CVE-2026-9134 Wordfence
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack
5.4 Medium Tiled Gallery Carousel Without JetPack Plugin tiled-gallery-carousel-without-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' ≤ 3.1 CVE-2026-5191 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter ≤ 6.4.15 CVE-2026-9243 Wordfence
6.4 Medium Splide Carousel Block Plugin splide-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'url' Block Attribute ≤ 1.7.1 CVE-2026-9022 Wordfence
6.4 Medium WP Carousel Free Plugin wp-carousel-free Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-caption' Attribute ≤ 2.7.10 CVE-2026-4665 Wordfence
6.4 Medium Slider Bootstrap Carousel Plugin slider-bootstrap-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.7 CVE-2026-4076 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
6.4 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode ≤ 7.4.8 CVE-2026-0738 Wordfence
6.4 Medium Multi Post Carousel by Category Plugin multi-post-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slides' Shortcode Attribute ≤ 1.4 CVE-2026-1275 Wordfence
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Broken Access Control No login needed ≤ 15.1 CVE-2026-27361 Patchstack
5.9 Medium Owl Carousel WP Plugin owl-carousel-wp Cross-Site Scripting ≤ 2.2.2 CVE-2026-22388 Patchstack
6.5 Medium Carousel Horizontal Posts Content Slider Plugin carousel-horizontal-posts-content-slider Cross-Site Scripting ≤ 3.3.2 CVE-2026-22347 Patchstack
7.1 High Magic Responsive Slider and Carousel Plugin magic_carousel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-49043 Patchstack
5.9 Medium Logo Slider , Logo Carousel , Logo showcase , Client Logo Plugin tc-logo-slider Cross-Site Scripting ≤ 1.8.1 CVE-2025-62121 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.1 CVE-2025-68996 Patchstack
6.5 Medium Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Cross-Site Scripting ≤ 15.2 Fixed in 15.3 CVE-2025-68548 Patchstack
4.3 Medium Image Slider by Ays- Responsive Slider and Carousel Plugin ays-slider Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed ≤ 2.7.0 CVE-2025-14454 Wordfence
6.4 Medium B Carousel Block – Responsive Image and Content Carousel Plugin b-carousel-block Broken Access Control Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.1.5 CVE-2025-12388 Wordfence
4.3 Medium Depicter — Popup & Slider Builder Plugin depicter Broken Access Control Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload ≤ 4.0.4 CVE-2025-11373 Wordfence
6.4 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 11.6.2 CVE-2025-8666 Wordfence
5.5 Medium Ultimate Multi Design Video Carousel Plugin ultimate-multi-design-video-carousel Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 1.4 CVE-2025-9372 Wordfence
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control ≤ 1.7.0 CVE-2025-57955 Patchstack
6.5 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58652 Patchstack
4.3 Medium Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid Plugin blog-designer-for-elementor Cross-Site Request Forgery Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-8481 Wordfence
5.9 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58820 Patchstack
3.5 Low Product Carousel Slider for Elementor Plugin ecommerce-product-carousel-slider-for-elementor Broken Access Control ≤ 2.1.3 CVE-2025-58816 Patchstack
6.4 Medium Anber Elementor Addon Plugin anber-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Carousel button link ≤ 1.0.1 CVE-2025-7440 Wordfence
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.0 Fixed in 15.1 CVE-2025-52728 Patchstack
6.4 Medium BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites Plugin blockspare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets ≤ 3.2.13.1 CVE-2025-4684 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 CVE-2025-6068 Wordfence
4.3 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function ≤ 1.6.0 CVE-2025-3863 Wordfence
8.8 High Owl carousel responsive Plugin responsive-owl-carousel SQL Injection Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.9 CVE-2025-5590 Wordfence
4.8 Medium Custom Post Carousels with Owl Plugin dd-post-carousel Cross-Site Scripting Contributor+ Stored XSS < 1.4.12 Fixed in 1.4.12 CVE-2025-5125 WPScan
6.4 Medium Simple Logo Carousel Plugin simple-logo-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9.3 CVE-2025-5700 Wordfence
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
8.8 High WP Posts Carousel Plugin wp-posts-carousel PHP Object Injection ≤ 1.3.12 Fixed in 1.3.13 CVE-2025-39358 Patchstack
4.8 Medium Post Slider and Carousel with Widget Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.10 Fixed in 3.2.10 CVE-2025-4567 WPScan
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
8.5 High Magic Responsive Slider and Carousel Plugin magic-carousel SQL Injection ≤ 1.6 Fixed in 1.6 CVE-2025-31640 Patchstack
8.5 High Multimedia Responsive Carousel with Image Video Audio Support Plugin multimedia-carousel SQL Injection ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-31928 Patchstack
6.5 Medium Product Carousel For WooCommerce – WoorouSell Plugin woorousell Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-32180 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only