WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Slider by 10Web Plugin slider-wd SQL Injection ≤ 1.2.63 CVE-2026-42710 Patchstack
6.5 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) ≤ 4.6.2 Fixed in 4.7.0 CVE-2026-105875 Patchstack
5.3 Medium Slider Pro Plugin sliderpro Information Disclosure Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images No login needed ≤ 1.0.0 CVE-2026-86786 WPScan
6.5 Medium Image Slider Widget Plugin image-slider-widget Cross-Site Scripting ≤ 1.1.130 CVE-2026-42700 Patchstack
6.4 Medium EmbedPress Plugin embedpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute ≤ 4.6.6 CVE-2026-92727 Wordfence
7.1 High LayerSlider Plugin layerslider Cross-Site Scripting No login needed ≤ 8.4.0 Fixed in 8.4.1 CVE-2026-97253 Patchstack
7.2 High Responsive Slider Gallery Plugin responsive-slider-gallery PHP Object Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-94122 Patchstack
6.4 Medium Smart Slider 3 Plugin smart-slider-3 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block ≤ 3.5.1.38 CVE-2026-14876 Wordfence
6.5 Medium WP Review Slider Pro Plugin SQL Injection Subscriber+ SQLi via Stored Template Filter < 12.7.12 Fixed in 12.7.12 CVE-2026-84097 WPScan
8.0 High WP Review Slider Pro Plugin Cross-Site Scripting Subscriber+ Stored XSS via Review Form Fields < 12.7.12 Fixed in 12.7.12 CVE-2026-84096 WPScan
8.0 High WP Review Slider Pro Plugin Cross-Site Scripting Subscriber+ Stored XSS via Review Import < 12.7.12 Fixed in 12.7.12 CVE-2026-84095 WPScan
7.2 High WP Yelp Review Slider Plugin wp-yelp-review-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) No login needed ≤ 9.2 CVE-2026-93778 Wordfence
6.8 Medium Master Slider Plugin master-slider Cross-Site Scripting Contributor+ Stored XSS via ms_slider Shortcode Attributes ≤ 3.11.2 CVE-2026-14844 WPScan
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value ≤ 4.5.13.1 CVE-2026-5399 Wordfence
6.8 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Contributor+ Stored XSS via Slider Elements' additional_settings < 5.9.9 Fixed in 5.9.9 CVE-2026-84028 WPScan
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter ≤ 4.27.6 CVE-2026-3853 Wordfence
6.4 Medium Smart Slider 3 Plugin smart-slider-3 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute ≤ 3.5.1.38 CVE-2026-15798 Wordfence
8.8 High Slider Hero Plugin Cross-Site Scripting Unauthenticated Stored XSS via Slider Type Change and Add-Slider Handlers No login needed < 9.1.3 Fixed in 9.1.3 CVE-2026-76789 WPScan
6.8 Medium Post Grid, Slider & Carousel Ultimate Plugin Cross-Site Scripting Contributor+ Stored XSS via Header Title Field < 1.8.1 Fixed in 1.8.1 CVE-2026-16260 WPScan
7.4 High Slider by 10Web Plugin slider-wd Cross-Site Request Forgery No login needed ≤ 1.2.63 CVE-2026-66635 Patchstack
7.5 High Depicter Slider Plugin depicter SQL Injection No login needed ≤ 4.8.0 CVE-2026-66622 Patchstack
4.9 Medium Slider Hero with Video Background, Animation Plugin slider-hero SQL Injection Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) ≤ 9.1.7 CVE-2026-17582 Wordfence
6.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute ≤ 1.4.0 CVE-2026-15726 Wordfence
5.4 Medium BNE Testimonials Plugin bne-testimonials Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode < 2.0.8.2 Fixed in 2.0.8.2 CVE-2026-15245 WPScan
6.4 Medium Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes ≤ 3.5.43 CVE-2026-12801 Wordfence
5.4 Medium Slick Slider Plugin Cross-Site Scripting Contributor+ Stored XSS via Gallery Shortcode < 0.5.3 Fixed in 0.5.3 CVE-2026-16537 WPScan
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting ≤ 3.111.0 CVE-2026-18400 Wordfence
4.9 Medium WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection Authenticated (Administrator+) SQL Injection ≤ 14.3 CVE-2026-11969 Wordfence
6.1 Medium Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Cross-Site Scripting Reflected Cross-Site Scripting via 'id' Parameter No login needed < 1.1.53 Fixed in 1.1.53 CVE-2026-18344 Wordfence
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
7.6 High WP Google Review Slider Plugin wp-google-places-review-slider SQL Injection ≤ 18.4 Fixed in 18.5 CVE-2026-66427 Patchstack
4.3 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.13.62 Fixed in 1.13.63 CVE-2026-65456 Patchstack
7.1 High Slider Pro Plugin sliderpro Cross-Site Scripting No login needed ≤ 4.8.13 Fixed in 4.8.14 CVE-2026-57699 Patchstack
4.9 Medium WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter ≤ 14.6 CVE-2026-15651 Wordfence
4.3 Medium Smart Slider 3 Plugin smart-slider-3 Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter ≤ 3.5.1.37 CVE-2026-12385 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field ≤ 7.7.6 CVE-2026-15097 Wordfence
6.4 Medium Mixed Media Gallery Blocks Plugin simply-gallery-block Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute ≤ 3.3.3.1 CVE-2026-5743 Wordfence
6.4 Medium Logo Slider Plugin logo-slider-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter ≤ 5.5 CVE-2026-13247 Wordfence
7.5 High Jssor Slider by jssor.com Plugin jssor-slider Path Traversal Unauthenticated Arbitrary File Read via 'url' Parameter No login needed ≤ 3.1.24 CVE-2026-14244 Wordfence
7.1 High Slider Revolution Plugin revslider Cross-Site Scripting No login needed 7.0.0 – 7.0.16 Fixed in 7.1.0 CVE-2026-57678 Patchstack
7.5 High WP Review Slider Pro Plugin SQL Injection Unauthenticated SQL Injection via 'notinstring' Parameter No login needed ≤ 12.7.2 CVE-2026-8441 Wordfence
4.4 Medium Product Video Gallery for Woocommerce Plugin product-video-gallery-slider-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter ≤ 1.5.1.8 CVE-2026-10104 Wordfence
6.1 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Scripting Reflected Cross-Site Scripting via 'place' Parameter No login needed ≤ 18.1 CVE-2026-13015 Wordfence
7.1 High Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2026-56039 Patchstack
7.1 High Master Slider Plugin master-slider Cross-Site Scripting No login needed ≤ 3.11.3 CVE-2026-56014 Patchstack
6.4 Medium Slideshow Gallery LITE Plugin slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute ≤ 1.8.5 CVE-2026-2021 Wordfence
8.1 High WP Review Slider Pro Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter ≤ 12.6.8 CVE-2026-8442 Wordfence
8.8 High WP Review Slider Pro Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via 'curselrevs' Parameter ≤ 12.6.8 CVE-2026-8444 Wordfence
8.8 High WP Review Slider Pro Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via 'stypes' Parameter ≤ 12.6.8 CVE-2026-8443 Wordfence
7.1 High Social Slider Feed Plugin instagram-slider-widget Cross-Site Scripting No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-39507 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only