WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–73 of 73 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-49300 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
8.8 High Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Local File Inclusion Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion ≤ 3.3.3 CVE-2024-11429 Wordfence
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High SrcSet Responsive Images Plugin truenorth-srcset Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-51702 Patchstack
7.1 High Responsive Data Table Plugin responsive-data-table Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51710 Patchstack
8.8 High Slider by 10Web – Responsive Image Slider Plugin slider-wd SQL Injection Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.2.57 CVE-2024-7150 Wordfence
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
7.1 High Simple Responsive Slider Plugin simple-responsive-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.2.5 CVE-2024-37954 Patchstack
8.5 High Responsive Image Gallery, Gallery Album Plugin gallery-album SQL Injection Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 CVE-2024-35750 Patchstack
8.8 High Responsive Owl Carousel for Elementor Plugin responsive-owl-carousel-elementor Local File Inclusion ≤ 1.2.0 CVE-2024-5345 Wordfence
7.7 High Bookly Plugin bookly-responsive-appointment-booking-tool Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 21.7.1 Fixed in 21.8 CVE-2023-26526 Patchstack
8.8 High Ditty – Responsive News Tickers, Sliders, and Lists Plugin ditty-news-ticker PHP Object Injection Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection ≤ 3.1.38 CVE-2024-3954 Wordfence
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
7.1 High Creative Image Slider – Responsive Slider Plugin creative-image-slider Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.5.0 CVE-2024-30447 Patchstack
8.5 High WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs SQL Injection ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-30497 Patchstack
7.5 High Responsive Theme responsive Broken Access Control Missing Authorization to HTML Injection No login needed ≤ 5.0.2 CVE-2024-2848 Wordfence
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1859 Wordfence
7.5 High Brooklyn | Creative Multi-Purpose Responsive Theme PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection ≤ 4.9.7.6 CVE-2024-24926 Patchstack
7.1 High Brooklyn | Creative Multi-Purpose Responsive Theme Cross-Site Scripting WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.9.7.6 CVE-2024-24927 Patchstack
8.8 High Ovic Responsive WPBakery Plugin PHP Object Injection Subscriber+ Option Update < 1.2.9 Fixed in 1.2.9 CVE-2023-5235 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only