WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 51–100 of 164 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 3.5 Low | Carousel, Slider, Gallery by WP Carousel | Cross-Site Scripting Editor+ Stored XSS |
< 2.6.9 Fixed in 2.6.9 |
CVE-2024-4002 |
WPScan | |
| 3.5 Low | Post Grid, Post Carousel, & List Category Posts | Cross-Site Scripting Editor+ Stored XSS |
< 2.4.28 Fixed in 2.4.28 |
CVE-2024-3996 |
WPScan | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.10.29 |
CVE-2025-1458 |
Wordfence | |
| 6.5 Medium | Carousel-of-post-images | Cross-Site Scripting |
≤ 1.07 |
CVE-2025-46536 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 5.10.28 |
CVE-2025-1457 |
Wordfence | |
| 6.5 Medium | Logo Carousel Slider | Cross-Site Scripting |
≤ 2.1.3 |
CVE-2025-39525 |
Patchstack | |
| 6.5 Medium | WP Posts Carousel | Cross-Site Scripting |
≤ 1.3.10 Fixed in 1.3.11 |
CVE-2025-39573 |
Patchstack | |
| 6.4 Medium | Logo Carousel Gutenberg Block | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter |
≤ 2.1.6 |
CVE-2025-2083 |
Wordfence | |
| 7.5 High | VG WooCarousel | Local File Inclusion |
≤ 1.3 |
CVE-2025-32153 |
Patchstack | |
| 6.5 Medium | Simple Owl Carousel | Cross-Site Scripting |
≤ 1.1.1 |
CVE-2025-31535 |
Patchstack | |
| 6.5 Medium | WP Posts Carousel | Cross-Site Scripting |
≤ 1.3.8 Fixed in 1.3.9 |
CVE-2025-31094 |
Patchstack | |
| 6.5 Medium | WP Posts Carousel | Cross-Site Scripting |
≤ 1.3.7 Fixed in 1.3.8 |
CVE-2025-30920 |
Patchstack | |
| 7.1 High | WIP WooCarousel Lite | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-30769 |
Patchstack | |
| 3.5 Low | Slider, Gallery, Carousel by MetaSlider | Cross-Site Scripting Editor+ Stored XSS |
< 3.95.0 Fixed in 3.95.0 |
CVE-2025-1203 |
WPScan | |
| 3.5 Low | Slider, Gallery, Carousel by MetaSlider | Cross-Site Scripting Editor+ Stored XSS |
< 3.95.0 Fixed in 3.95.0 |
CVE-2025-1062 |
WPScan | |
| 4.9 Medium | Thumbnail carousel slider | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.4 |
CVE-2019-25222 |
Wordfence | |
| 4.3 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates |
≤ 2.4.29 |
CVE-2024-12114 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size |
≤ 2.4.29 |
CVE-2024-12119 |
Wordfence | |
| 6.4 Medium | WP Posts Carousel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_play_timeout Parameter |
≤ 1.3.7 |
CVE-2025-1491 |
Wordfence | |
| 5.1 Medium | FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed |
2.4.29 |
CVE-2025-22624 |
Fluid Attacks | |
| 7.5 High | VG PostCarousel | Local File Inclusion |
≤ 1.1 |
CVE-2025-27272 |
Patchstack | |
| 9.8 Critical | Responsive Slider by MetaSlider | PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed |
≤ 3.94.0 Fixed in 3.95.0 |
CVE-2025-26763 |
Patchstack | |
| 3.5 Low | Carousel, Slider, Gallery by WP Carousel | Cross-Site Scripting Admin+ Stored XSS |
< 2.7.4 Fixed in 2.7.4 |
CVE-2024-13314 |
WPScan | |
| 6.1 Medium | WP Dream Carousel | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.0.1b |
CVE-2024-13331 |
WPScan | |
| 7.1 High | Post Carousel Slider | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.0.1 |
CVE-2025-23977 |
Patchstack | |
| 6.5 Medium | Post Grid, Slider & Carousel Ultimate | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion |
≤ 1.6.10 Fixed in 1.7 |
CVE-2025-24782 |
Patchstack | |
| 6.4 Medium | Divi Carousel Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Logo Carousel Widgets |
≤ 2.0.4 |
CVE-2025-0350 |
Wordfence | |
| 5.9 Medium | Product Carousel Slider & Grid Ultimate for WooCommerce | Cross-Site Scripting |
≤ 1.10.0 Fixed in 1.10.1 |
CVE-2025-24681 |
Patchstack | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.6.10 |
CVE-2024-13408 |
Wordfence | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() |
≤ 1.6.10 |
CVE-2024-13409 |
Wordfence | |
| 9.3 Critical | Multiple Carousel | SQL Injection No login needed |
≤ 2.0 |
CVE-2025-22553 |
Patchstack | |
| 6.5 Medium | WpF Ultimate Carousel | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.11 |
CVE-2025-23933 |
Patchstack | |
| 6.5 Medium | Product Carousel For WooCommerce – WoorouSell | Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) |
≤ 1.1.0 |
CVE-2025-22724 |
Patchstack | |
| 7.1 High | Post Carousel & Slider | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.4 |
CVE-2025-22750 |
Patchstack | |
| 4.3 Medium | FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export |
≤ 6.0.0 |
CVE-2024-10536 |
Wordfence | |
| 4.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Broken Access Control Missing Authorization |
≤ 5.10.12 |
CVE-2024-11852 |
Wordfence | |
| 7.1 High | ECT Product Carousel | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.9 |
CVE-2024-54412 |
Patchstack | |
| 7.1 High | jCarousel | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2024-54437 |
Patchstack | |
| 6.4 Medium | Post Carousel & Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.3 |
CVE-2024-11770 |
Wordfence | |
| 5.3 Medium | Carousel Slider | Broken Access Control No login needed |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2023-41848 |
Patchstack | |
| 5.3 Medium | Owl Carousel | Broken Access Control No login needed |
≤ 0.5.3 |
CVE-2022-44578 |
Patchstack | |
| 8.8 High | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' |
≤ 1.9.10 |
CVE-2024-12040 |
Wordfence | |
| 5.3 Medium | Meta slider and carousel with lightbox | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.7 |
CVE-2023-25703 |
Patchstack | |
| 6.4 Medium | Depicter — Popup & Slider Builder | Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting |
≤ 3.2.1 |
CVE-2024-4633 |
Wordfence | |
| 6.4 Medium | WIP WooCarousel Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.6 |
CVE-2024-11779 |
Wordfence | |
| 6.5 Medium | Post Carousel Slider for Elementor | Cross-Site Scripting |
≤ 1.5.0 Fixed in 1.6.0 |
CVE-2024-53749 |
Patchstack | |
| 6.5 Medium | Vertical Carousel | Cross-Site Scripting |
≤ 1.0.2 |
CVE-2024-53756 |
Patchstack | |
| 8.1 High | Sky Addons – Elementor Addons with Widgets & Templates | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed |
≤ 2.6.1 |
CVE-2024-11601 |
Wordfence | |
| 8.1 High | Sky Addons – Elementor Addons with Widgets & Templates | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update |
≤ 2.6.2 |
CVE-2024-11104 |
Wordfence | |
| 6.5 Medium | WE – Client Logo Carousel | Cross-Site Scripting Client Logo Carousel plugin <= 1.4 - Cross Site Scripting (XSS) |
≤ 1.4 |
CVE-2024-51821 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.