WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–25 of 25 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Gmedia Photo Gallery Plugin grand-media SQL Injection No login needed ≤ 1.25.1 CVE-2026-39785 Patchstack
9.3 Critical Books Gallery Plugin wp-books-gallery SQL Injection No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-96822 Patchstack
9.3 Critical InPost Gallery Plugin inpost-gallery SQL Injection No login needed ≤ 2.1.4.6 Fixed in 2.1.5 CVE-2026-39574 Patchstack
9.3 Critical Contest Gallery Plugin contest-gallery SQL Injection No login needed ≤ 28.1.6 Fixed in 28.1.7 CVE-2026-40771 Patchstack
9.8 Critical Contest Gallery Pro Plugin contest-gallery-pro Privilege Escalation No login needed ≤ 29.0.1 Fixed in 29.0.2 CVE-2026-42680 Patchstack
9.9 Critical SimpLy Gallery Plugin simply-gallery-block Remote Code Execution Arbitrary Code Execution ≤ 3.3.2 Fixed in 3.3.2.1 CVE-2026-25345 Patchstack
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Account Takeover No login needed ≤ 28.1.2.2 Fixed in 28.1.3 CVE-2026-25035 Patchstack
9.8 Critical DZS Video Gallery Plugin dzs-videogallery PHP Object Injection No login needed ≤ 12.37 CVE-2025-47552 Patchstack
9.8 Critical Flickr Gallery Plugin flickr-gallery PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.5.3 Fixed in 1.5.3 CVE-2017-20207 Wordfence
10.0 Critical FW Gallery Plugin fw-gallery Arbitrary File Upload No login needed ≤ 8.0.0 CVE-2025-49414 Patchstack
9.1 Critical BEAF Plugin beaf-before-and-after-gallery Arbitrary File Upload ≤ 4.6.10 Fixed in 4.6.11 CVE-2025-47549 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack
9.1 Critical WP Load Gallery Plugin wp-load-gallery Arbitrary File Upload ≤ 2.1.6 CVE-2025-23942 Patchstack
9.9 Critical Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Arbitrary File Upload ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-54370 Patchstack
9.3 Critical Nabz Image Gallery Plugin nabz-image-gallery SQL Injection No login needed ≤ v1.00 CVE-2024-55981 Patchstack
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover No login needed ≤ 24.0.7 CVE-2024-11103 Wordfence
9.8 Critical Lis Video Gallery Plugin lis-video-gallery PHP Object Injection No login needed ≤ 0.2.1 CVE-2024-52430 Patchstack
10.0 Critical Devexhub Gallery Plugin devexhub-gallery Arbitrary File Upload No login needed ≤ 2.0.1 CVE-2024-52373 Patchstack
10.0 Critical HB AUDIO GALLERY Plugin hb-audio-gallery Arbitrary File Upload No login needed ≤ 3.0 CVE-2024-51790 Patchstack
9.8 Critical Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery SQL Injection Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection No login needed ≤ 24.0.3 CVE-2024-10687 Wordfence
9.9 Critical WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Arbitrary File Upload ≤ 1.5.7 CVE-2024-49260 Patchstack
9.9 Critical WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection ≤ 4.8.5 CVE-2024-8436 Wordfence
9.3 Critical WordPress Picture / Portfolio / Media Gallery Plugin nimble-portfolio Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.0.1 CVE-2024-5021 Wordfence
9.8 Critical Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.13 CVE-2024-4258 Wordfence
9.1 Critical Photo Gallery by 10Web - Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename ≤ 1.8.19 CVE-2024-0221 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only