WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed < 3.6.12 Fixed in 3.6.12 CVE-2026-16561 WPScan
4.3 Medium Contest Gallery Plugin contest-gallery Information Disclosure Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts < 30.0.7 Fixed in 30.0.7 CVE-2026-16056 WPScan
6.5 Medium Contest Gallery Plugin contest-gallery Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library < 30.0.7 Fixed in 30.0.7 CVE-2026-16057 WPScan
7.5 High Gallery for Google Photos Plugin Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-15236 WPScan
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.6 Fixed in 30.0.7 CVE-2026-65447 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
6.5 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting ≤ 3.33 Fixed in 3.34 CVE-2026-66434 Patchstack
6.1 Medium Document Gallery Plugin document-gallery Cross-Site Scripting Reflected XSS via dg_generate_gallery No login needed < 5.1.1 Fixed in 5.1.1 CVE-2026-12982 WPScan
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting 2.14.25 – 2.14.30 Fixed in 2.14.31 CVE-2026-65475 Patchstack
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting ≤ 2.7.7.29 Fixed in 2.7.7.30 CVE-2026-65519 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Arbitrary File Deletion ≤ 1.6.5 Fixed in 1.6.6 CVE-2026-57696 Patchstack
5.9 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Scripting ≤ 1.16.3 CVE-2026-24628 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-57695 Patchstack
6.4 Medium Mixed Media Gallery Blocks Plugin simply-gallery-block Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute ≤ 3.3.3.1 CVE-2026-5743 Wordfence
6.4 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter ≤ 4.8.5 CVE-2026-12123 Wordfence
6.5 Medium Mosaic Gallery – Advanced Gallery Plugin mosaic-gallery-advanced-gallery Cross-Site Scripting Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2026-57755 Patchstack
4.4 Medium Product Video Gallery for Woocommerce Plugin product-video-gallery-slider-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter ≤ 1.5.1.8 CVE-2026-10104 Wordfence
7.5 High Video Gallery Plugin youtube-showcase Information Disclosure Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter ≤ 4.0.3 CVE-2026-12923 Wordfence
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 30.0.0 Fixed in 30.0.1 CVE-2026-57662 Patchstack
8.5 High Gallery Plugin gallery-plugin SQL Injection ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-57642 Patchstack
7.2 High Cincopa video and media plug-in Plugin video-playlist-and-gallery-plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed ≤ 1.163 CVE-2026-10092 Wordfence
6.4 Medium Slideshow Gallery LITE Plugin slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute ≤ 1.8.5 CVE-2026-2021 Wordfence
8.8 High Contest Gallery Plugin contest-gallery Privilege Escalation Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter ≤ 30.0.2 CVE-2026-12165 Wordfence
6.5 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control No login needed ≤ 1.12.5 Fixed in 1.12.6 CVE-2026-54190 Patchstack
9.3 Critical InPost Gallery Plugin inpost-gallery SQL Injection No login needed ≤ 2.1.4.6 Fixed in 2.1.5 CVE-2026-39574 Patchstack
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting ≤ 2.14.23 Fixed in 2.14.24 CVE-2026-42688 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Information Disclosure Sensitive Data Exposure ≤ 28.1.7 Fixed in 29.0.0 CVE-2026-42660 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Other Other Vulnerability Type No login needed ≤ 28.1.7 Fixed in 29.0.0 CVE-2026-42657 Patchstack
6.5 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 28.1.6 Fixed in 29.0.0 CVE-2026-42656 Patchstack
9.3 Critical Contest Gallery Plugin contest-gallery SQL Injection No login needed ≤ 28.1.6 Fixed in 28.1.7 CVE-2026-40771 Patchstack
7.2 High Modula Image Gallery Plugin modula-best-grid-gallery PHP Object Injection ≤ 2.14.18 Fixed in 2.14.19 CVE-2026-39481 Patchstack
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
4.3 Medium Meow Gallery Plugin meow-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Shortcode creation ≤ 5.4.4 CVE-2026-1291 Wordfence
6.4 Medium Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin foogallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter ≤ 3.1.31 CVE-2026-9134 Wordfence
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter ≤ 1.8.41 CVE-2026-9829 Wordfence
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
5.4 Medium Tiled Gallery Carousel Without JetPack Plugin tiled-gallery-carousel-without-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' ≤ 3.1 CVE-2026-5191 Wordfence
9.8 Critical Contest Gallery Pro Plugin contest-gallery-pro Privilege Escalation No login needed ≤ 29.0.1 Fixed in 29.0.2 CVE-2026-42680 Patchstack
6.5 Medium Photo Gallery by 10Web Plugin photo-gallery SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute ≤ 1.8.40 CVE-2026-7048 Wordfence
6.4 Medium Post Categories Gallery Plugin post-category-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.0 CVE-2026-8867 Wordfence
4.3 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-27424 Patchstack
4.3 Medium Photo Gallery, Sliders, Proofing and Themes Plugin nextgen-gallery Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API ≤ 4.2.0 CVE-2026-6566 Wordfence
7.5 High Contest Gallery Plugin contest-gallery SQL Injection Unauthenticated SQL Injection No login needed ≤ 28.1.6 CVE-2026-8912 Wordfence
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter ≤ 1.12.4 CVE-2026-5361 Wordfence
6.4 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting WordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL 1.4.2 CVE-2021-47951 VulnCheck
6.4 Medium Filterable Portfolio Gallery Plugin fg-gallery Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS 1.0 CVE-2021-47929 VulnCheck

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only