WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 52 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross-Site Scripting via 'thumb_url' Parameter No login needed ≤ 1.8.46 CVE-2026-92974 Wordfence
8.8 High Photo Gallery by 10Web Plugin photo-gallery PHP Object Injection ≤ 1.8.46 Fixed in 1.8.47 CVE-2026-102377 Patchstack
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute ≤ 1.8.44 CVE-2026-85652 Wordfence
8.8 High Mapster WP Maps Plugin mapster-wp-maps Privilege Escalation Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter ≤ 1.23.0 CVE-2026-12954 Wordfence
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.44 CVE-2026-86311 Wordfence
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected XSS via title and paged Parameters No login needed < 1.8.44 Fixed in 1.8.44 CVE-2026-12865 WPScan
4.9 Medium Photo Gallery by Ays Plugin gallery-photo-gallery SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 6.8.2 CVE-2026-76006 Wordfence
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter ≤ 1.8.41 CVE-2026-9829 Wordfence
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute ≤ 1.8.40 CVE-2026-7048 Wordfence
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Request Forgery No login needed ≤ 1.8.37 Fixed in 1.8.38 CVE-2026-32330 Patchstack
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.38 Fixed in 1.8.39 CVE-2026-27360 Patchstack
4.3 Medium ACF Photo Gallery Field Plugin navz-photo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification ≤ 3.0 CVE-2025-12081 Wordfence
7.1 High WordPress Photo Gallery Plugin photo-gallery-portfolio Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-53240 Patchstack
5.3 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Broken Access Control Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion No login needed ≤ 1.8.36 CVE-2026-1036 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.5 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting ≤ 6.3.8 Fixed in 6.3.9 CVE-2025-57947 Patchstack
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.29 Fixed in 1.8.29 CVE-2024-8670 WPScan
7.1 High ZooEffect Plugin 1-jquery-photo-gallery-slideshow-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.11 CVE-2025-26954 Patchstack
6.1 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter No login needed ≤ 1.8.34 CVE-2025-2269 Wordfence
6.1 Medium Photo Gallery Plugin photo-gallery Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.8.34 Fixed in 1.8.34 CVE-2025-0613 WPScan
3.5 Low Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.33 Fixed in 1.8.33 CVE-2024-13124 WPScan
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
6.4 Medium 3D Photo Gallery Plugin 3d-photo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13751 Wordfence
6.5 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.2 CVE-2025-24697 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
6.1 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Cross-Site Scripting Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2024-12403 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.15 Fixed in 1.8.16 CVE-2023-33995 Patchstack
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.31 Fixed in 1.8.31 CVE-2024-10704 WPScan
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.8.30 CVE-2024-9878 Wordfence
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.28 Fixed in 1.8.28 CVE-2024-5968 WPScan
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.27 Fixed in 1.8.28 CVE-2024-44043 Patchstack
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
4.3 Medium ACF Photo Gallery Field Plugin navz-photo-gallery Broken Access Control ≤ 2.6 Fixed in 2.7 CVE-2024-23518 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.25 Fixed in 1.8.26 CVE-2024-35628 Patchstack
6.8 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function ≤ 1.8.23 CVE-2024-5481 Wordfence
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG ≤ 1.8.23 CVE-2024-5426 Wordfence
7.5 High Photo Gallery Plugin new-photo-gallery PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode ≤ 1.4.2 CVE-2024-1896 Wordfence
5.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control No login needed ≤ 1.8.20 Fixed in 1.8.21 CVE-2024-33586 Patchstack
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.21 Fixed in 1.8.22 CVE-2024-32583 Patchstack
5.5 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG ≤ 1.8.21 CVE-2024-2296 Wordfence
7.1 High Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.2 Fixed in 5.5.3 CVE-2024-29919 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only