WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 501–525 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-30236 Patchstack
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 21.3.2 Fixed in 21.3.2.1 CVE-2024-30238 Patchstack
5.4 Medium Post Video Players Plugin video-playlist-and-gallery-plugin Cross-Site Request Forgery No login needed ≤ 1.159 Fixed in 1.160 CVE-2024-23515 Patchstack
6.5 Medium Portfolio Gallery – Image Gallery Plugin portfolio-filter-gallery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-29769 Patchstack
5.9 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Scripting ≤ 1.15.16 Fixed in 1.15.17 CVE-2024-29921 Patchstack
7.1 High Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.2 Fixed in 5.5.3 CVE-2024-29919 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck
6.4 Medium Easy Social Feed – Social Photos Gallery – Post Feed – Like Box Plugin easy-facebook-likebox Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.5.4 CVE-2024-1278 Wordfence
5.4 Medium Photos and Files Contest Gallery Plugin Cross-Site Scripting Author+ Stored Cross Site Scripting < 21.3.1 Fixed in 21.3.1 CVE-2024-1487 WPScan
8.8 High Vimeography: Vimeo Video Gallery Plugin vimeography PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.3.2 CVE-2024-0825 Wordfence
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1859 Wordfence
4.3 Medium Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation Plugin gs-logo-slider Cross-Site Request Forgery WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2023-51530 Patchstack
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery ≤ 5.9.8 CVE-2024-1171 Wordfence
4.4 Medium Best WordPress Gallery Plugin – FooGallery Plugin foogallery Cross-Site Scripting FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings ≤ 2.4.7 CVE-2024-0604 Wordfence
5.4 Medium Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin contest-gallery Cross-Site Request Forgery WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 21.2.8.4 Fixed in 21.2.9 CVE-2024-24887 Patchstack
9.1 Critical Photo Gallery by 10Web - Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename ≤ 1.8.19 CVE-2024-0221 Wordfence
6.5 Medium Portfolio & Image Gallery for WordPress | PowerFolio Plugin portfolio-elementor Cross-Site Scripting WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) ≤ 3.1 Fixed in 3.1.1 CVE-2024-22150 Patchstack
5.9 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting WordPress Robo Gallery Plugin <= 3.2.17 is vulnerable to Cross Site Scripting (XSS) ≤ 3.2.17 Fixed in 3.2.18 CVE-2024-22295 Patchstack
4.3 Medium Envira Gallery Lite Plugin envira-gallery-lite Broken Access Control Missing Authorization to Gallery Modification via envira_gallery_insert_images ≤ 1.8.7.2 CVE-2023-6742 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Widget ≤ 1.8.18 CVE-2023-6924 Wordfence
6.4 Medium FooGallery Premium Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.3, ≤ 2.4.8 CVE-2023-6747 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only