WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–79 of 79 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium GS Shots for Dribbble Plugin gs-dribbble-portfolio Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-56263 Patchstack
4.3 Medium Perfect Portfolio Plugin perfect-portfolio Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-37435 Patchstack
6.4 Medium Portfolio – Filterable Masonry Portfolio Gallery for Professionals Plugin portfolio-pro Cross-Site Scripting Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-11900 Wordfence
6.4 Medium Companion Portfolio – Responsive Portfolio Plugin companion-portfolio Cross-Site Scripting Responsive Portfolio Plugin <= 2.4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0.1 CVE-2024-11867 Wordfence
4.3 Medium Portfolio and Projects Plugin portfolio-and-projects Broken Access Control ≤ 1.3.7 Fixed in 1.3.8 CVE-2023-39995 Patchstack
5.4 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Broken Access Control ≤ 1.6.7 Fixed in 1.6.8 CVE-2023-32593 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
6.5 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.8 CVE-2019-25221 Wordfence
6.4 Medium WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more Plugin gs-portfolio Cross-Site Scripting A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.3 CVE-2024-11765 Wordfence
6.4 Medium WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout Plugin gs-pinterest-portfolio Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.8 CVE-2024-11453 Wordfence
6.5 Medium Elementor Portfolio Builder Plugin portfolio-builder-elementor Cross-Site Scripting ≤ 1.0.0 CVE-2024-52486 Patchstack
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
6.5 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-49302 Patchstack
5.3 Medium Sight – Professional Image Gallery and Portfolio Plugin sight Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed ≤ 1.1.2 CVE-2024-9025 Wordfence
6.4 Medium WPZOOM Portfolio Lite – Filterable Portfolio Plugin wpzoom-portfolio Cross-Site Scripting Filterable Portfolio Plugin <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.4.4 CVE-2024-8276 Wordfence
6.4 Medium Premium Portfolio Features for Phlox Plugin auxin-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.4 CVE-2024-1384 Wordfence
6.4 Medium Premium Portfolio Features for Phlox Plugin auxin-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios' ≤ 2.3.2 CVE-2024-3587 Wordfence
6.4 Medium Portfolio Gallery – Image Gallery Plugin portfolio-filter-gallery Cross-Site Scripting Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 1.6.4 CVE-2024-6262 Wordfence
9.3 Critical WordPress Picture / Portfolio / Media Gallery Plugin nimble-portfolio Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.0.1 CVE-2024-5021 Wordfence
8.6 High Phlox Portfolio Plugin auxin-portfolio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-38399 Patchstack
6.4 Medium Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter ≤ 3.3.2 CVE-2024-4363 Wordfence
6.4 Medium Sydney Toolbox Plugin sydney-toolbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget ≤ 1.31 CVE-2024-4473 Wordfence
6.5 Medium WP Portfolio Theme wp-portfolio Cross-Site Scripting ≤ 2.4 Fixed in 2.5 CVE-2024-33537 Patchstack
5.9 Medium Filterable Portfolio Plugin filterable-portfolio Cross-Site Scripting ≤ 1.6.4 CVE-2024-4234 Patchstack
6.5 Medium Portfolio Gallery – Image Gallery Plugin portfolio-filter-gallery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-29769 Patchstack
6.5 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-30192 Patchstack
6.5 Medium Portfolio & Image Gallery for WordPress | PowerFolio Plugin portfolio-elementor Cross-Site Scripting WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) ≤ 3.1 Fixed in 3.1.1 CVE-2024-22150 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only