WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 51–100 of 525 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Sunshine Photo Cart | Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed |
< 3.6.12 Fixed in 3.6.12 |
CVE-2026-16561 |
WPScan | |
| 4.3 Medium | Contest Gallery | Information Disclosure Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16056 |
WPScan | |
| 6.5 Medium | Contest Gallery | Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16057 |
WPScan | |
| 7.5 High | Gallery for Google Photos | Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed |
< 1.2.1 Fixed in 1.2.1 |
CVE-2026-15236 |
WPScan | |
| 7.1 High | Contest Gallery | Cross-Site Scripting No login needed |
≤ 30.0.6 Fixed in 30.0.7 |
CVE-2026-65447 |
Patchstack | |
| 6.5 Medium | Gallery PhotoBlocks | Cross-Site Scripting |
≤ 1.3.3 Fixed in 1.3.4 |
CVE-2026-66448 |
Patchstack | |
| 6.5 Medium | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | Cross-Site Scripting |
≤ 3.33 Fixed in 3.34 |
CVE-2026-66434 |
Patchstack | |
| 6.1 Medium | Document Gallery | Cross-Site Scripting Reflected XSS via dg_generate_gallery No login needed |
< 5.1.1 Fixed in 5.1.1 |
CVE-2026-12982 |
WPScan | |
| 6.5 Medium | Modula Image Gallery | Cross-Site Scripting |
2.14.25 – 2.14.30 Fixed in 2.14.31 |
CVE-2026-65475 |
Patchstack | |
| 6.5 Medium | Photo Gallery | Cross-Site Scripting |
≤ 2.7.7.29 Fixed in 2.7.7.30 |
CVE-2026-65519 |
Patchstack | |
| 7.1 High | Picture Gallery | Arbitrary File Deletion |
≤ 1.6.5 Fixed in 1.6.6 |
CVE-2026-57696 |
Patchstack | |
| 5.9 Medium | Photo Gallery by Supsystic | Cross-Site Scripting |
≤ 1.16.3 |
CVE-2026-24628 |
Patchstack | |
| 7.1 High | Document Gallery | Cross-Site Scripting No login needed |
≤ 5.1.0 Fixed in 5.1.1 |
CVE-2026-57695 |
Patchstack | |
| 6.4 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute |
≤ 3.3.3.1 |
CVE-2026-5743 |
Wordfence | |
| 6.4 Medium | All-in-One Video Gallery | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter |
≤ 4.8.5 |
CVE-2026-12123 |
Wordfence | |
| 6.5 Medium | Mosaic Gallery – Advanced Gallery | Cross-Site Scripting Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) |
≤ 1.2.0 |
CVE-2026-57755 |
Patchstack | |
| 4.4 Medium | Product Video Gallery for Woocommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter |
≤ 1.5.1.8 |
CVE-2026-10104 |
Wordfence | |
| 7.5 High | Video Gallery | Information Disclosure Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter |
≤ 4.0.3 |
CVE-2026-12923 |
Wordfence | |
| 8.5 High | Contest Gallery | SQL Injection |
≤ 30.0.0 Fixed in 30.0.1 |
CVE-2026-57662 |
Patchstack | |
| 8.5 High | Gallery | SQL Injection |
≤ 4.7.8 Fixed in 4.7.9 |
CVE-2026-57642 |
Patchstack | |
| 7.2 High | Cincopa video and media plug-in | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed |
≤ 1.163 |
CVE-2026-10092 |
Wordfence | |
| 6.4 Medium | Slideshow Gallery LITE | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute |
≤ 1.8.5 |
CVE-2026-2021 |
Wordfence | |
| 8.8 High | Contest Gallery | Privilege Escalation Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter |
≤ 30.0.2 |
CVE-2026-12165 |
Wordfence | |
| 6.5 Medium | Envira Photo Gallery | Broken Access Control No login needed |
≤ 1.12.5 Fixed in 1.12.6 |
CVE-2026-54190 |
Patchstack | |
| 9.3 Critical | InPost Gallery | SQL Injection No login needed |
≤ 2.1.4.6 Fixed in 2.1.5 |
CVE-2026-39574 |
Patchstack | |
| 6.5 Medium | Modula Image Gallery | Cross-Site Scripting |
≤ 2.14.23 Fixed in 2.14.24 |
CVE-2026-42688 |
Patchstack | |
| 6.5 Medium | Contest Gallery | Information Disclosure Sensitive Data Exposure |
≤ 28.1.7 Fixed in 29.0.0 |
CVE-2026-42660 |
Patchstack | |
| 6.5 Medium | Contest Gallery | Other Other Vulnerability Type No login needed |
≤ 28.1.7 Fixed in 29.0.0 |
CVE-2026-42657 |
Patchstack | |
| 6.5 Medium | Contest Gallery | Cross-Site Scripting |
≤ 28.1.6 Fixed in 29.0.0 |
CVE-2026-42656 |
Patchstack | |
| 9.3 Critical | Contest Gallery | SQL Injection No login needed |
≤ 28.1.6 Fixed in 28.1.7 |
CVE-2026-40771 |
Patchstack | |
| 7.2 High | Modula Image Gallery | PHP Object Injection |
≤ 2.14.18 Fixed in 2.14.19 |
CVE-2026-39481 |
Patchstack | |
| 7.5 High | HB Audio Gallery Lite | Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed |
1.0.0 |
CVE-2016-20081 |
VulnCheck | |
| 4.3 Medium | Meow Gallery | Broken Access Control Missing Authorization to Authenticated (Author+) Shortcode creation |
≤ 5.4.4 |
CVE-2026-1291 |
Wordfence | |
| 6.4 Medium | Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter |
≤ 3.1.31 |
CVE-2026-9134 |
Wordfence | |
| 7.5 High | Mac Photo Gallery | Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed |
3.0 |
CVE-2017-20250 |
VulnCheck | |
| 8.2 High | Apptha Slider Gallery | SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed |
1.0 |
CVE-2017-20249 |
VulnCheck | |
| 7.5 High | Apptha Slider Gallery | Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed |
1.0 |
CVE-2017-20248 |
VulnCheck | |
| 8.2 High | PICA Photo Gallery | SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed |
1.0 |
CVE-2017-20247 |
VulnCheck | |
| 6.5 Medium | Photo Gallery by 10Web | SQL Injection Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter |
≤ 1.8.41 |
CVE-2026-9829 |
Wordfence | |
| 7.6 High | Photo Gallery by 10Web | SQL Injection |
≤ 1.8.41 Fixed in 1.8.42 |
CVE-2026-49771 |
Patchstack | |
| 5.4 Medium | Tiled Gallery Carousel Without JetPack | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' |
≤ 3.1 |
CVE-2026-5191 |
Wordfence | |
| 9.8 Critical | Contest Gallery Pro | Privilege Escalation No login needed |
≤ 29.0.1 Fixed in 29.0.2 |
CVE-2026-42680 |
Patchstack | |
| 6.5 Medium | Photo Gallery by 10Web | SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute |
≤ 1.8.40 |
CVE-2026-7048 |
Wordfence | |
| 6.4 Medium | Post Categories Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.0 |
CVE-2026-8867 |
Wordfence | |
| 4.3 Medium | Image Photo Gallery Final Tiles Grid | Broken Access Control |
≤ 3.6.11 Fixed in 3.6.12 |
CVE-2026-27424 |
Patchstack | |
| 4.3 Medium | Photo Gallery, Sliders, Proofing and Themes | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API |
≤ 4.2.0 |
CVE-2026-6566 |
Wordfence | |
| 7.5 High | Contest Gallery | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 28.1.6 |
CVE-2026-8912 |
Wordfence | |
| 6.4 Medium | Envira Gallery | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter |
≤ 1.12.4 |
CVE-2026-5361 |
Wordfence | |
| 6.4 Medium | Picture Gallery | Cross-Site Scripting WordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL |
1.4.2 |
CVE-2021-47951 |
VulnCheck | |
| 6.4 Medium | Filterable Portfolio Gallery | Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS |
1.0 |
CVE-2021-47929 |
VulnCheck |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.