WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 143 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
7.1 High DZS Video Gallery Plugin dzs-videogallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.25 CVE-2025-32300 Patchstack
8.8 High DZS Video Gallery Plugin dzs-videogallery PHP Object Injection ≤ 12.25 CVE-2025-47553 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.26 Fixed in 2.7.7.27 CVE-2025-69084 Patchstack
7.1 High Zielke Design Project Gallery Plugin zielke-design-project-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23705 Patchstack
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template' ≤ 3.59.12 CVE-2025-13641 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Import ZIP 4.5.4 – 4.5.7 CVE-2025-12966 Wordfence
8.8 High PostGallery Plugin postgallery Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.12.5 CVE-2025-13543 Wordfence
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence
7.2 High Modula Plugin modula-best-grid-gallery Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion 2.13.1 – 2.13.2 CVE-2025-13645 Wordfence
8.1 High WP AUDIO GALLERY Plugin wp-audio-gallery Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter ≤ 2.0 CVE-2025-13322 Wordfence
7.1 High Image Gallery block – Create and display photo gallery/photo album. Plugin 3d-image-gallery Authentication Bypass Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication ≤ 1.0.7 Fixed in 2.0.0 CVE-2025-49394 Patchstack
7.5 High InPost Gallery Plugin inpost-gallery Local File Inclusion ≤ 2.1.4.5 CVE-2025-57889 Patchstack
8.5 High New Simple Gallery Plugin new-simple-gallery SQL Injection ≤ 8.0 CVE-2025-58881 Patchstack
7.1 High NextGEN Gallery Search Plugin nextgen-gallery-search-galleries Cross-Site Scripting No login needed ≤ 2.12 CVE-2025-53224 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
7.5 High Assistant for NextGEN Gallery Plugin assistant-for-nextgen-gallery Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.0.9 CVE-2025-7641 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.1.0 CVE-2025-7725 Wordfence
8.8 High Visual Art | Gallery Plugin visual-arts PHP Object Injection ≤ 2.4 CVE-2025-31422 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 26.0.6 Fixed in 26.0.7 CVE-2025-48291 Patchstack
8.5 High Pixelating image slideshow gallery Plugin pixelating-image-slideshow-gallery SQL Injection ≤ 8.0 CVE-2025-30979 Patchstack
8.5 High iFrame Images Gallery Plugin wp-iframe-images-gallery SQL Injection ≤ 9.0 CVE-2025-30969 Patchstack
8.5 High Gallery Widget Plugin gallery-widget SQL Injection ≤ 1.2.1 CVE-2025-28969 Patchstack
7.5 High Gmedia Photo Gallery Plugin grand-media Local File Inclusion ≤ 1.23.0 Fixed in 1.24.0 CVE-2025-53257 Patchstack
8.1 High FW Gallery Plugin fw-gallery Local File Inclusion No login needed ≤ 8.0.0 CVE-2025-49416 Patchstack
7.5 High Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Plugin aeroscroll-gallery Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed ≤ 1.0.13 CVE-2025-49451 Patchstack
8.6 High FW Gallery Plugin fw-gallery Arbitrary File Deletion No login needed ≤ 8.0.0 CVE-2025-49415 Patchstack
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
7.1 High WordPress Photo Gallery – Image Gallery Plugin photo-image-gallery Cross-Site Scripting Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-27291 Patchstack
7.1 High T&P Gallery Slider Plugin tp-gallery-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-32527 Patchstack
7.1 High GB Gallery Slideshow Plugin gb-gallery-slideshow Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-32649 Patchstack
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8.0 CVE-2025-22263 Patchstack
7.1 High ZooEffect Plugin 1-jquery-photo-gallery-slideshow-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.11 CVE-2025-26954 Patchstack
7.1 High Smart Product Gallery Slider Plugin smart-product-gallery-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.4 CVE-2025-31392 Patchstack
7.6 High Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member SQL Injection ≤ 1.1.3 CVE-2025-32121 Patchstack
7.1 High Rio Video Gallery Plugin rio-video-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.6 CVE-2025-31566 Patchstack
7.1 High ULTIMATE VIDEO GALLERY Plugin ultimate-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22566 Patchstack
7.1 High NextGEN Gallery Voting Plugin nextgen-gallery-voting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 CVE-2025-28869 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
7.1 High SW Plus Plugin shalom-world-media-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-25108 Patchstack
7.1 High Easy Gallery Plugin simple-gallery-odihost Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23487 Patchstack
7.1 High Attach Gallery Posts Plugin attach-gallery-posts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-23441 Patchstack
7.2 High Album Gallery – WordPress Gallery Plugin new-album-gallery PHP Object Injection WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta ≤ 1.6.3 CVE-2024-13833 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
7.1 High Add Linked Images To Gallery Plugin add-linked-images-to-gallery-v01 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-27277 Patchstack
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
7.1 High Singsys -Awesome Gallery Plugin awesome-gallery-singsys Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23748 Patchstack
7.6 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 25.1.0 Fixed in 25.1.2 CVE-2025-22693 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only