WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 451–500 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function ≤ 1.8.23 CVE-2024-5481 Wordfence
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG ≤ 1.8.23 CVE-2024-5426 Wordfence
6.5 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0 CVE-2024-4194 Wordfence
6.5 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting ≤ 1.5.11 Fixed in 1.5.12 CVE-2024-34759 Patchstack
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block ≤ 2.12.8 CVE-2024-1815 Wordfence
5.3 Medium YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin youtube-showcase Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed ≤ 3.3.6 CVE-2024-3268 Wordfence
6.0 Medium Unite Gallery Lite Plugin unite-gallery-lite Local File Inclusion ≤ 1.7.59 Fixed in 1.7.60 CVE-2023-33310 Patchstack
4.3 Medium Nextgen Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.1 Fixed in 3.59.1 CVE-2024-2744 WPScan
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode ≤ 3.6.5 CVE-2024-4670 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-site Scriping via 'Sina Particle Layer' ≤ 3.5.3 CVE-2024-4373 Wordfence
6.4 Medium Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter ≤ 3.3.2 CVE-2024-4363 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Cross-Site Scripting ≤ 3.5.3 CVE-2024-4333 Wordfence
6.4 Medium Gallery Block (Meow Gallery) Plugin meow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.3 CVE-2024-4386 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify ≤ 2.5.0 CVE-2024-3989 Wordfence
5.9 Medium Featured Content Gallery Plugin featured-content-gallery Cross-Site Scripting ≤ 3.2.0 CVE-2024-34424 Patchstack
4.8 Medium Ungallery Plugin ungallery Cross-Site Scripting Stored XSS via CSRF ≤ 2.2.4 CVE-2024-3582 WPScan
4.3 Medium Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery Plugin new-video-gallery Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-34377 Patchstack
5.3 Medium Robo Gallery Plugin robo-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.18 Fixed in 3.2.19 CVE-2024-34382 Patchstack
5.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode ≤ 1.0.272 CVE-2024-3340 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via featured image ≤ 3.6.4 CVE-2024-4033 Wordfence
7.5 High Grid Gallery – Photo Image Grid Gallery Plugin new-grid-gallery PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode ≤ 1.4.3 CVE-2024-1897 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
7.5 High Photo Gallery Plugin new-photo-gallery PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode ≤ 1.4.2 CVE-2024-1896 Wordfence
5.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control No login needed ≤ 1.8.20 Fixed in 1.8.21 CVE-2024-33586 Patchstack
6.4 Medium Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.21 - Authenticated (Author+) Cross-Site Scripting ≤ 2.7.7.21 CVE-2024-4035 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Sina Fancy Text Widget ≤ 3.5.2 CVE-2024-3988 Wordfence
8.8 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode ≤ 4.6.18 CVE-2024-3293 Wordfence
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.21 Fixed in 1.8.22 CVE-2024-32583 Patchstack
4.3 Medium BEAF Plugin beaf-before-and-after-gallery Cross-Site Request Forgery No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2024-32433 Patchstack
4.3 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Request Forgery No login needed ≤ 1.7.8 CVE-2024-31354 Patchstack
4.3 Medium WP Matterport Shortcode Plugin shortcode-gallery-for-matterport-showcase Cross-Site Request Forgery No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2024-32109 Patchstack
6.4 Medium Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows Plugin ml-slider Cross-Site Scripting Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode ≤ 3.70.0 CVE-2024-3285 Wordfence
8.5 High Slideshow Gallery Plugin slideshow-gallery SQL Injection Auth. SQL Injection ≤ 1.7.8 CVE-2024-31355 Patchstack
6.5 Medium WordPress Gallery Exporter Plugin wp-gallery-exporter Path Traversal Arbitrary File Download ≤ 1.3 CVE-2024-31342 Patchstack
5.3 Medium Slideshow Gallery Plugin slideshow-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.8 CVE-2024-31353 Patchstack
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.4.14 CVE-2024-2081 Wordfence
6.4 Medium Sydney Toolbox Plugin sydney-toolbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery ≤ 1.28 CVE-2024-3208 Wordfence
5.3 Medium WordPress Gallery Plugin – NextGEN Gallery Plugin nextgen-gallery Broken Access Control NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 3.59 CVE-2024-3097 Wordfence
6.1 Medium Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS No login needed < 2.3.11 Fixed in 2.3.11 CVE-2024-1664 WPScan
5.5 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG ≤ 1.8.21 CVE-2024-2296 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' ≤ 2.6.3 CVE-2024-2949 Wordfence
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields ≤ 2.4.14 CVE-2024-2471 Wordfence
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
6.5 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) ≤ 2.0.3 CVE-2024-31120 Patchstack
4.3 Medium Easy Social Feed Plugin easy-facebook-likebox Cross-Site Request Forgery Social Photos Gallery – Post Feed – Like Box plugin <= 6.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 6.5.6 CVE-2024-30526 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-30428 Patchstack
5.4 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery PHP Object Injection Responsive Lightbox Gallery <= 1.9.9 - Authenticated (Contributor+) PHP Object Injection ≤ 1.9.9 CVE-2024-1858 Wordfence
6.4 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode ≤ 3.13 CVE-2024-2475 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only