WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 51–100 of 164 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Editor+ Stored XSS < 2.6.9 Fixed in 2.6.9 CVE-2024-4002 WPScan
3.5 Low Post Grid, Post Carousel, & List Category Posts Plugin Cross-Site Scripting Editor+ Stored XSS < 2.4.28 Fixed in 2.4.28 CVE-2024-3996 WPScan
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.10.29 CVE-2025-1458 Wordfence
6.5 Medium Carousel-of-post-images Plugin carousel-of-post-images Cross-Site Scripting ≤ 1.07 CVE-2025-46536 Patchstack
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.28 CVE-2025-1457 Wordfence
6.5 Medium Logo Carousel Slider Plugin logo-carousel-slider Cross-Site Scripting ≤ 2.1.3 CVE-2025-39525 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.10 Fixed in 1.3.11 CVE-2025-39573 Patchstack
6.4 Medium Logo Carousel Gutenberg Block Plugin awesome-logo-carousel-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter ≤ 2.1.6 CVE-2025-2083 Wordfence
7.5 High VG WooCarousel Plugin vg-woocarousel Local File Inclusion ≤ 1.3 CVE-2025-32153 Patchstack
6.5 Medium Simple Owl Carousel Plugin simple-owl-carousel Cross-Site Scripting ≤ 1.1.1 CVE-2025-31535 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-31094 Patchstack
6.5 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2025-30920 Patchstack
7.1 High WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30769 Patchstack
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1203 WPScan
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1062 WPScan
4.9 Medium Thumbnail carousel slider Plugin wp-responsive-thumbnail-slider SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2019-25222 Wordfence
4.3 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates ≤ 2.4.29 CVE-2024-12114 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size ≤ 2.4.29 CVE-2024-12119 Wordfence
6.4 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_play_timeout Parameter ≤ 1.3.7 CVE-2025-1491 Wordfence
5.1 Medium FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed 2.4.29 CVE-2025-22624 Fluid Attacks
7.5 High VG PostCarousel Plugin vg-postcarousel Local File Inclusion ≤ 1.1 CVE-2025-27272 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Admin+ Stored XSS < 2.7.4 Fixed in 2.7.4 CVE-2024-13314 WPScan
6.1 Medium WP Dream Carousel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1b CVE-2024-13331 WPScan
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
6.4 Medium Divi Carousel Lite Plugin wow-carousel-for-divi-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Logo Carousel Widgets ≤ 2.0.4 CVE-2025-0350 Wordfence
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
9.3 Critical Multiple Carousel Plugin multicarousel SQL Injection No login needed ≤ 2.0 CVE-2025-22553 Patchstack
6.5 Medium WpF Ultimate Carousel Plugin wpf-ultimate-carousel Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2025-23933 Patchstack
6.5 Medium Product Carousel For WooCommerce – WoorouSell Plugin woorousell Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-22724 Patchstack
7.1 High Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-22750 Patchstack
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
4.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Broken Access Control Missing Authorization ≤ 5.10.12 CVE-2024-11852 Wordfence
7.1 High ECT Product Carousel Plugin ect-product-carousel Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.9 CVE-2024-54412 Patchstack
7.1 High jCarousel Plugin jcarousel-for-wordpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54437 Patchstack
6.4 Medium Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11770 Wordfence
5.3 Medium Carousel Slider Plugin carousel-slider Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-41848 Patchstack
5.3 Medium Owl Carousel Plugin owl-carousel Broken Access Control No login needed ≤ 0.5.3 CVE-2022-44578 Patchstack
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
5.3 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.7 CVE-2023-25703 Patchstack
6.4 Medium Depicter — Popup & Slider Builder Plugin depicter Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.2.1 CVE-2024-4633 Wordfence
6.4 Medium WIP WooCarousel Lite Plugin wip-woocarousel-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.6 CVE-2024-11779 Wordfence
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
6.5 Medium Vertical Carousel Plugin vertical-carousel-slider Cross-Site Scripting ≤ 1.0.2 CVE-2024-53756 Patchstack
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
6.5 Medium WE – Client Logo Carousel Plugin we-client-logo-carousel Cross-Site Scripting Client Logo Carousel plugin <= 1.4 - Cross Site Scripting (XSS) ≤ 1.4 CVE-2024-51821 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only