WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.11 Fixed in 3.0.12 CVE-2026-105876 Patchstack
6.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS via Gallery Crop Dimensions < 1.16.1 Fixed in 1.16.1 CVE-2026-104653 WPScan
6.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS via Gallery Image ID < 1.16.1 Fixed in 1.16.1 CVE-2026-104652 WPScan
9.3 Critical Gmedia Photo Gallery Plugin grand-media SQL Injection No login needed ≤ 1.25.1 CVE-2026-39785 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.1 CVE-2026-39781 Patchstack
6.5 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting ≤ 3.6.13 Fixed in 3.6.14 CVE-2026-104409 Patchstack
6.1 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross-Site Scripting via 'thumb_url' Parameter No login needed ≤ 1.8.46 CVE-2026-92974 Wordfence
6.8 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Contributor+ Stored XSS via Image Gallery Item URL Attribute < 2.9.3 Fixed in 2.9.3 CVE-2026-88782 WPScan
8.8 High Photo Gallery by 10Web Plugin photo-gallery PHP Object Injection ≤ 1.8.46 Fixed in 1.8.47 CVE-2026-102377 Patchstack
7.1 High Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting No login needed ≤ 3.36 Fixed in 3.37 CVE-2026-97290 Patchstack
5.4 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.21.0 Fixed in 1.21.1 CVE-2026-102399 Patchstack
9.3 Critical Books Gallery Plugin wp-books-gallery SQL Injection No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-96822 Patchstack
7.5 High NextGEN Gallery Plugin nextgen-gallery Path Traversal Arbitrary File Download No login needed ≤ 4.5.0 Fixed in 4.5.1 CVE-2026-94123 Patchstack
7.2 High Responsive Slider Gallery Plugin responsive-slider-gallery PHP Object Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-94122 Patchstack
7.5 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters No login needed ≤ 3.0.1 CVE-2026-89406 Wordfence
8.1 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter ≤ 3.0.2 CVE-2026-92713 Wordfence
2.7 Low Meow Gallery Plugin meow-gallery Information Disclosure Author+ Draft and Private Post Disclosure via fetch_posts < 5.5.5 Fixed in 5.5.5 CVE-2026-92423 WPScan
6.5 Medium Meow Gallery Plugin meow-gallery Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route No login needed < 5.5.5 Fixed in 5.5.5 CVE-2026-92422 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Plugin Image Settings Update < 4.5.0 Fixed in 4.5.0 CVE-2026-81654 WPScan
4.2 Medium NextGEN Gallery Plugin Broken Access Control Authenticated Arbitrary Gallery Image Deletion via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81653 WPScan
2.7 Low NextGEN Gallery Plugin Information Disclosure Contributor+ Image Metadata Disclosure via IDOR 3.59.5 – < 4.5.0 Fixed in 4.5.0 CVE-2026-81652 WPScan
3.1 Low NextGEN Gallery Plugin Broken Access Control Authenticated Cross-Gallery Settings Modification via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81651 WPScan
7.2 High NextGEN Gallery Plugin Arbitrary File Upload Authenticated Arbitrary File Upload via ZIP Import < 4.5.0 Fixed in 4.5.0 CVE-2026-81650 WPScan
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute ≤ 1.8.44 CVE-2026-85652 Wordfence
8.8 High Mapster WP Maps Plugin mapster-wp-maps Privilege Escalation Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter ≤ 1.23.0 CVE-2026-12954 Wordfence
4.3 Medium Filter Gallery Plugin filter-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'image_id' Parameter via ufg_save_gallery AJAX Action ≤ 1.1.4 CVE-2026-89138 Wordfence
8.1 High Filter Gallery Plugin filter-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter ≤ 1.1.4 CVE-2026-89413 Wordfence
7.1 High Filter Gallery Plugin filter-gallery Broken Access Control Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check 1.1.2 – < 1.1.5 Fixed in 1.1.5 CVE-2026-90978 WPScan
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.44 CVE-2026-86311 Wordfence
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
6.4 Medium Gallery : FooGallery Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute ≤ 3.3.2 CVE-2026-85414 Wordfence
6.8 Medium CatFolders Document Gallery Plugin Cross-Site Scripting Author+ Stored XSS via titleTag Block Attribute < 2.0.7 Fixed in 2.0.7 CVE-2026-84930 WPScan
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected XSS via title and paged Parameters No login needed < 1.8.44 Fixed in 1.8.44 CVE-2026-12865 WPScan
4.9 Medium Photo Gallery by Ays Plugin gallery-photo-gallery SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 6.8.2 CVE-2026-76006 Wordfence
5.3 Medium CatFolders Document Gallery Pro Plugin Broken Access Control Unauthenticated Missing Authorization via download-all No login needed 2.0.6 – < 2.0.7 Fixed in 2.0.7 CVE-2026-19430 WPScan
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description ≤ 1.12.4 CVE-2026-3423 Wordfence
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'delay' Shortcode Attribute ≤ 3.6.12 CVE-2026-4559 Wordfence
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting No login needed ≤ 11.1.2 CVE-2026-73184 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.5 Fixed in 30.0.6 CVE-2026-61986 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure No login needed ≤ 1.16.20 CVE-2026-74007 Patchstack
7.2 High Gallery by BestWebSoft Plugin gallery-plugin SQL Injection Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys ≤ 4.7.9 CVE-2026-2497 Wordfence
7.5 High CatFolders Document Gallery Plugin Information Disclosure Unauthenticated Attachment Disclosure via REST API No login needed < 2.0.7 Fixed in 2.0.7 CVE-2026-19717 WPScan
6.4 Medium Video Gallery Plugin youtube-showcase Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode ≤ 4.0.4 CVE-2026-15790 Wordfence
6.5 Medium Contest Gallery Plugin contest-gallery SQL Injection Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' ≤ 30.0.7 CVE-2026-16586 Wordfence
5.4 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting Author+ Stored XSS via Attachment Alt-Text < 5.5.2 Fixed in 5.5.2 CVE-2026-15386 WPScan
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
5.4 Medium Slick Slider Plugin Cross-Site Scripting Contributor+ Stored XSS via Gallery Shortcode < 0.5.3 Fixed in 0.5.3 CVE-2026-16537 WPScan
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting ≤ 3.111.0 CVE-2026-18400 Wordfence
7.5 High Contest Gallery Plugin contest-gallery Authentication Bypass Unauthenticated Login-Protection and 2FA Bypass via post_cg_login < 30.0.7 Fixed in 30.0.7 CVE-2026-16055 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only