WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 501–550 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32682 Patchstack
5.4 Medium Prime Slider – Addons for Elementor Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) <= 3.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.0 CVE-2024-1730 Wordfence
8.3 High Master Slider Plugin master-slider PHP Object Injection No login needed ≤ 3.9.5 Fixed in 3.9.7 CVE-2024-32600 Patchstack
7.1 High Slider by 10Web Plugin slider-wd Cross-Site Scripting No login needed ≤ 1.2.54 Fixed in 1.2.55 CVE-2024-32578 Patchstack
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.9.8 Fixed in 3.9.9 CVE-2024-32580 Patchstack
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget ≤ 5.6.0 CVE-2024-1429 Wordfence
6.5 Medium Sangar Slider Plugin sangar-slider-lite Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2024-32091 Patchstack
5.4 Medium Testimonial Slider Plugin testimonial-slider Cross-Site Scripting Admin+ Stored XSS < 2.3.8 Fixed in 2.3.8 CVE-2024-1746 WPScan
4.7 Medium Carousel Slider Plugin carousel-slider Cross-Site Scripting Editor+ Stored XSS No login needed < 2.2.7 Fixed in 2.2.7 CVE-2024-1712 WPScan
6.4 Medium Smart Slider 3 Plugin smart-slider-3 Broken Access Control Missing Authorization to Limited File Upload ≤ 3.5.1.22 CVE-2024-3027 Wordfence
5.4 Medium Loan Repayment Calculator and Application Form Plugin quick-interest-slider Cross-Site Request Forgery No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-31263 Patchstack
4.3 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Request Forgery No login needed ≤ 1.7.8 CVE-2024-31354 Patchstack
6.4 Medium Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows Plugin ml-slider Cross-Site Scripting Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode ≤ 3.70.0 CVE-2024-3285 Wordfence
8.5 High Slideshow Gallery Plugin slideshow-gallery SQL Injection Auth. SQL Injection ≤ 1.7.8 CVE-2024-31355 Patchstack
5.3 Medium Slideshow Gallery Plugin slideshow-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.8 CVE-2024-31353 Patchstack
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence
6.4 Medium Revslider Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 6.6.20 CVE-2024-2306 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget ≤ 8.3.4 CVE-2024-1464 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget ≤ 8.3.4 CVE-2024-1466 Wordfence
6.4 Medium Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' ≤ 2.6.3 CVE-2024-2949 Wordfence
9.8 Critical LayerSlider Plugin SQL Injection The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user suppl… No login needed 7.9.11 – 7.10.0 CVE-2024-2879 Wordfence
7.1 High Yoo Slider Plugin yoo-slider Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2024-31106 Patchstack
6.5 Medium B Slider - Slider for your block editor Plugin b-slider Cross-Site Scripting ≤ 1.1.12 Fixed in 1.1.13 CVE-2024-30432 Patchstack
6.5 Medium GS Testimonial Slider Plugin gs-testimonial Cross-Site Scripting ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-30443 Patchstack
7.1 High Creative Image Slider – Responsive Slider Plugin creative-image-slider Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.5.0 CVE-2024-30447 Patchstack
5.9 Medium Slider by Supsystic Plugin slider-by-supsystic Cross-Site Scripting ≤ 1.8.10 Fixed in 1.8.11 CVE-2024-30448 Patchstack
5.4 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery PHP Object Injection Responsive Lightbox Gallery <= 1.9.9 - Authenticated (Contributor+) PHP Object Injection ≤ 1.9.9 CVE-2024-1858 Wordfence
7.6 High Slider by Supsystic Plugin slider-by-supsystic SQL Injection ≤ 1.8.10 Fixed in 1.8.11 CVE-2024-30237 Patchstack
6.5 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Scripting ≤ 0.5.8.1 Fixed in 0.5.8.2 CVE-2024-29762 Patchstack
6.5 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting ≤ 3.13.1 Fixed in 3.13.2 CVE-2024-30186 Patchstack
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Cross-Site Scripting ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-29925 Patchstack
5.9 Medium Slider Hero Plugin slider-hero Cross-Site Scripting ≤ 8.6.1 Fixed in 8.7.0 CVE-2024-29922 Patchstack
7.1 High New RoyalSlider Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2024-30195 Patchstack
4.3 Medium Testimonial Slider Plugin testimonial-slider Broken Access Control Author+ Settings Update < 2.3.7 Fixed in 2.3.7 CVE-2024-1745 WPScan
4.3 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 3.11.10 Fixed in 3.11.11 CVE-2024-24883 Patchstack
5.4 Medium Depicter Slider Plugin depicter Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-51491 Patchstack
7.5 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate PHP Object Injection Authenticated(Contributor+) PHP Object Injection ≤ 1.9.7 CVE-2024-1950 Wordfence
7.5 High Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Plugin logo-showcase-ultimate PHP Object Injection Logo Carousel, Logo Slider & Logo Grid <= 1.3.8 - Authenticated(Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1951 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Thumbnail Slider Widget ≤ 1.12.12 CVE-2024-1391 Wordfence
8.8 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup ≤ 1.6.7 CVE-2024-2006 Wordfence
6.4 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Mercury Widget ≤ 3.13.2 CVE-2024-1508 Wordfence
6.4 Medium Prime Slider – Addons For Elementor Plugin Cross-Site Scripting Addons For Elementor <= 3.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rubix Widget ≤ 3.13.3 CVE-2024-1507 Wordfence
5.3 Medium Team Circle Image Slider With Lightbox Plugin circle-image-slider-with-lightbox Cross-Site Request Forgery The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on… No login needed 1.0 CVE-2015-10130 Wordfence
6.4 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget ≤ 3.13.1 CVE-2024-1506 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.9.10 CVE-2024-1449 Wordfence
4.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback ≤ 3.9.9 CVE-2024-0611 Wordfence
5.4 Medium Master Slider - Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed ≤ 3.9.10 CVE-2023-6326 Wordfence
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1859 Wordfence
4.3 Medium Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation Plugin gs-logo-slider Cross-Site Request Forgery WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2023-51530 Patchstack
5.3 Medium WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin myshopkit-popup-smartbar-slidein Information Disclosure WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.0.9 CVE-2024-1436 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only