WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 51–100 of 143 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Famous - Responsive Image And Video Grid Gallery | Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2025-27004 |
Patchstack | |
| 7.1 High | DZS Video Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 12.25 |
CVE-2025-32300 |
Patchstack | |
| 8.8 High | DZS Video Gallery | PHP Object Injection |
≤ 12.25 |
CVE-2025-47553 |
Patchstack | |
| 7.1 High | Photo Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.7.7.26 Fixed in 2.7.7.27 |
CVE-2025-69084 |
Patchstack | |
| 7.1 High | Zielke Design Project Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.0 |
CVE-2025-23705 |
Patchstack | |
| 8.8 High | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | Local File Inclusion NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template' |
≤ 3.59.12 |
CVE-2025-13641 |
Wordfence | |
| 8.8 High | All-in-One Video Gallery | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Import ZIP |
4.5.4 – 4.5.7 |
CVE-2025-12966 |
Wordfence | |
| 8.8 High | PostGallery | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 1.12.5 |
CVE-2025-13543 |
Wordfence | |
| 7.5 High | Modula | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition |
2.13.1 – 2.13.2 |
CVE-2025-13646 |
Wordfence | |
| 7.2 High | Modula | Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion |
2.13.1 – 2.13.2 |
CVE-2025-13645 |
Wordfence | |
| 8.1 High | WP AUDIO GALLERY | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter |
≤ 2.0 |
CVE-2025-13322 |
Wordfence | |
| 7.1 High | Image Gallery block – Create and display photo gallery/photo album. | Authentication Bypass Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication |
≤ 1.0.7 Fixed in 2.0.0 |
CVE-2025-49394 |
Patchstack | |
| 7.5 High | InPost Gallery | Local File Inclusion |
≤ 2.1.4.5 |
CVE-2025-57889 |
Patchstack | |
| 8.5 High | New Simple Gallery | SQL Injection |
≤ 8.0 |
CVE-2025-58881 |
Patchstack | |
| 7.1 High | NextGEN Gallery Search | Cross-Site Scripting No login needed |
≤ 2.12 |
CVE-2025-53224 |
Patchstack | |
| 8.8 High | Vertical scroll slideshow gallery v2 | SQL Injection |
≤ 9.1 |
CVE-2025-49897 |
Patchstack | |
| 7.5 High | Assistant for NextGEN Gallery | Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed |
≤ 1.0.9 |
CVE-2025-7641 |
Wordfence | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.1.0 |
CVE-2025-7725 |
Wordfence | |
| 8.8 High | Visual Art | Gallery | PHP Object Injection |
≤ 2.4 |
CVE-2025-31422 |
Patchstack | |
| 7.1 High | Contest Gallery | Cross-Site Scripting No login needed |
≤ 26.0.6 Fixed in 26.0.7 |
CVE-2025-48291 |
Patchstack | |
| 8.5 High | Pixelating image slideshow gallery | SQL Injection |
≤ 8.0 |
CVE-2025-30979 |
Patchstack | |
| 8.5 High | iFrame Images Gallery | SQL Injection |
≤ 9.0 |
CVE-2025-30969 |
Patchstack | |
| 8.5 High | Gallery Widget | SQL Injection |
≤ 1.2.1 |
CVE-2025-28969 |
Patchstack | |
| 7.5 High | Gmedia Photo Gallery | Local File Inclusion |
≤ 1.23.0 Fixed in 1.24.0 |
CVE-2025-53257 |
Patchstack | |
| 8.1 High | FW Gallery | Local File Inclusion No login needed |
≤ 8.0.0 |
CVE-2025-49416 |
Patchstack | |
| 7.5 High | Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery | Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed |
≤ 1.0.13 |
CVE-2025-49451 |
Patchstack | |
| 8.6 High | FW Gallery | Arbitrary File Deletion No login needed |
≤ 8.0.0 |
CVE-2025-49415 |
Patchstack | |
| 7.5 High | Apptha Slider Gallery | Path Traversal Arbitrary File Read No login needed |
≤ 2.5 |
CVE-2025-31050 |
Patchstack | |
| 7.1 High | WordPress Photo Gallery – Image Gallery | Cross-Site Scripting Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.4 |
CVE-2025-27291 |
Patchstack | |
| 7.1 High | T&P Gallery Slider | Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed |
≤ 1.2 |
CVE-2025-32527 |
Patchstack | |
| 7.1 High | GB Gallery Slideshow | Cross-Site Scripting No login needed |
≤ 1.3 |
CVE-2025-32649 |
Patchstack | |
| 7.1 High | Global Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 8.8.0 |
CVE-2025-22263 |
Patchstack | |
| 7.1 High | ZooEffect | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.11 |
CVE-2025-26954 |
Patchstack | |
| 7.1 High | Smart Product Gallery Slider | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0.4 |
CVE-2025-31392 |
Patchstack | |
| 7.6 High | Video & Photo Gallery for Ultimate Member | SQL Injection |
≤ 1.1.3 |
CVE-2025-32121 |
Patchstack | |
| 7.1 High | Rio Video Gallery | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.3.6 |
CVE-2025-31566 |
Patchstack | |
| 7.1 High | ULTIMATE VIDEO GALLERY | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2025-22566 |
Patchstack | |
| 7.1 High | NextGEN Gallery Voting | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.7.6 |
CVE-2025-28869 |
Patchstack | |
| 7.1 High | Picture Gallery | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.6.3 Fixed in 1.6.4 |
CVE-2025-26581 |
Patchstack | |
| 7.2 High | Gallery by BestWebSoft – Customizable Image and Photo Galleries | PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection |
≤ 4.7.3 |
CVE-2024-13906 |
Wordfence | |
| 7.1 High | SW Plus | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1 |
CVE-2025-25108 |
Patchstack | |
| 7.1 High | Easy Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2025-23487 |
Patchstack | |
| 7.1 High | Attach Gallery Posts | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6 |
CVE-2025-23441 |
Patchstack | |
| 7.2 High | Album Gallery – WordPress Gallery | PHP Object Injection WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta |
≤ 1.6.3 |
CVE-2024-13833 |
Wordfence | |
| 7.2 High | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 26.0.0.1 |
CVE-2025-1513 |
Wordfence | |
| 7.1 High | Tribulant Gallery Voting | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.1 Fixed in 1.3 |
CVE-2025-26931 |
Patchstack | |
| 7.1 High | Add Linked Images To Gallery | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.4 |
CVE-2025-27277 |
Patchstack | |
| 8.8 High | Photo Gallery ( Responsive ) | Cross-Site Request Forgery CSRF to Privilege Escalation No login needed |
≤ 4.0 |
CVE-2025-27276 |
Patchstack | |
| 7.1 High | Singsys -Awesome Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-23748 |
Patchstack | |
| 7.6 High | Contest Gallery | SQL Injection |
≤ 25.1.0 Fixed in 25.1.2 |
CVE-2025-22693 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.