WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 143 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.1 CVE-2026-39781 Patchstack
8.8 High Photo Gallery by 10Web Plugin photo-gallery PHP Object Injection ≤ 1.8.46 Fixed in 1.8.47 CVE-2026-102377 Patchstack
7.1 High Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting No login needed ≤ 3.36 Fixed in 3.37 CVE-2026-97290 Patchstack
7.5 High NextGEN Gallery Plugin nextgen-gallery Path Traversal Arbitrary File Download No login needed ≤ 4.5.0 Fixed in 4.5.1 CVE-2026-94123 Patchstack
7.2 High Responsive Slider Gallery Plugin responsive-slider-gallery PHP Object Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-94122 Patchstack
7.5 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters No login needed ≤ 3.0.1 CVE-2026-89406 Wordfence
8.1 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter ≤ 3.0.2 CVE-2026-92713 Wordfence
7.2 High NextGEN Gallery Plugin Arbitrary File Upload Authenticated Arbitrary File Upload via ZIP Import < 4.5.0 Fixed in 4.5.0 CVE-2026-81650 WPScan
8.8 High Mapster WP Maps Plugin mapster-wp-maps Privilege Escalation Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter ≤ 1.23.0 CVE-2026-12954 Wordfence
8.1 High Filter Gallery Plugin filter-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter ≤ 1.1.4 CVE-2026-89413 Wordfence
7.1 High Filter Gallery Plugin filter-gallery Broken Access Control Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check 1.1.2 – < 1.1.5 Fixed in 1.1.5 CVE-2026-90978 WPScan
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected XSS via title and paged Parameters No login needed < 1.8.44 Fixed in 1.8.44 CVE-2026-12865 WPScan
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting No login needed ≤ 11.1.2 CVE-2026-73184 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.5 Fixed in 30.0.6 CVE-2026-61986 Patchstack
7.2 High Gallery by BestWebSoft Plugin gallery-plugin SQL Injection Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys ≤ 4.7.9 CVE-2026-2497 Wordfence
7.5 High CatFolders Document Gallery Plugin Information Disclosure Unauthenticated Attachment Disclosure via REST API No login needed < 2.0.7 Fixed in 2.0.7 CVE-2026-19717 WPScan
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
7.5 High Contest Gallery Plugin contest-gallery Authentication Bypass Unauthenticated Login-Protection and 2FA Bypass via post_cg_login < 30.0.7 Fixed in 30.0.7 CVE-2026-16055 WPScan
7.5 High Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed < 3.6.12 Fixed in 3.6.12 CVE-2026-16561 WPScan
7.5 High Gallery for Google Photos Plugin Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-15236 WPScan
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.6 Fixed in 30.0.7 CVE-2026-65447 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Arbitrary File Deletion ≤ 1.6.5 Fixed in 1.6.6 CVE-2026-57696 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-57695 Patchstack
7.5 High Video Gallery Plugin youtube-showcase Information Disclosure Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter ≤ 4.0.3 CVE-2026-12923 Wordfence
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 30.0.0 Fixed in 30.0.1 CVE-2026-57662 Patchstack
8.5 High Gallery Plugin gallery-plugin SQL Injection ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-57642 Patchstack
7.2 High Cincopa video and media plug-in Plugin video-playlist-and-gallery-plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed ≤ 1.163 CVE-2026-10092 Wordfence
8.8 High Contest Gallery Plugin contest-gallery Privilege Escalation Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter ≤ 30.0.2 CVE-2026-12165 Wordfence
7.2 High Modula Image Gallery Plugin modula-best-grid-gallery PHP Object Injection ≤ 2.14.18 Fixed in 2.14.19 CVE-2026-39481 Patchstack
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
7.5 High Contest Gallery Plugin contest-gallery SQL Injection Unauthenticated SQL Injection No login needed ≤ 28.1.6 CVE-2026-8912 Wordfence
7.5 High Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Local File Inclusion ≤ <= 3.5.1 Fixed in 3.5.2 CVE-2026-32537 Patchstack
8.1 High Contest Gallery Plugin contest-gallery Privilege Escalation Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion No login needed ≤ 28.1.5 CVE-2026-4021 Wordfence
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion ≤ 4.0.4 CVE-2026-1463 Wordfence
7.6 High Meow Gallery Plugin meow-gallery SQL Injection ≤ 5.4.4 Fixed in 5.4.5 CVE-2026-32418 Patchstack
7.5 High Contest Gallery Plugin contest-gallery SQL Injection Unauthenticated SQL Injection No login needed ≤ 28.1.4 CVE-2026-3180 Wordfence
8.8 High Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored XSS No login needed 1.7.0 – < 2.6.1 Fixed in 2.6.1 CVE-2025-15386 WPScan
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin slider-responsive-slideshow PHP Object Injection Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Object Injection ≤ 1.5.4 CVE-2026-22346 Patchstack
8.8 High Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery Plugin new-image-gallery PHP Object Injection Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin <= 1.6.0 - PHP Object Injection ≤ 1.6.0 Fixed in 1.6.1 CVE-2026-22345 Patchstack
8.8 High WP AUDIO GALLERY Plugin wp-audio-gallery Path Traversal Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation ≤ 2.0 CVE-2025-13603 Wordfence
7.5 High PhotoStack Gallery Plugin photostack-gallery SQL Injection Unauthenticated SQL Injection via 'postid' Parameter No login needed ≤ 0.4.1 CVE-2026-2024 Wordfence
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
8.5 High DZS Video Gallery Plugin dzs-videogallery SQL Injection ≤ 12.39 Fixed in 12.40 CVE-2025-49049 Patchstack
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass ≤ 4.5.7 CVE-2025-12957 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only