WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–100 of 168 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.6 Fixed in 2.0.7 |
CVE-2025-53202 |
Patchstack | |
| 5.4 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 2.5.2 Fixed in 2.5.2 |
CVE-2025-5093 |
WPScan | |
| 6.4 Medium | Responsive Food and Drink Menu | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via display_pdf_menus Shortcode |
≤ 2.3 |
CVE-2025-6378 |
Wordfence | |
| 4.3 Medium | eDS Responsive Menu | Broken Access Control |
≤ 1.2 |
CVE-2025-49971 |
Patchstack | |
| 4.3 Medium | Responsive Plus | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2025-49856 |
Patchstack | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2025-49881 |
Patchstack | |
| 5.4 Medium | Responsive Flipbooks | Broken Access Control |
≤ 1.0 |
CVE-2025-24776 |
Patchstack | |
| 4.3 Medium | FastBook | Cross-Site Request Forgery No login needed |
≤ 1.1 |
CVE-2025-26593 |
Patchstack | |
| 6.5 Medium | ShiftNav – Responsive Mobile Menu | Cross-Site Scripting Responsive Mobile Menu plugin <= 1.8 - Cross Site Scripting (XSS) |
≤ 1.8 Fixed in 1.8.1 |
CVE-2025-49243 |
Patchstack | |
| 5.4 Medium | Responsive Plus | Broken Access Control |
≤ 3.2.0 Fixed in 3.2.1 |
CVE-2025-48335 |
Patchstack | |
| 4.8 Medium | Ditty – Responsive News Tickers, Sliders, and Lists | Cross-Site Scripting Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS |
< 3.1.52 Fixed in 3.1.52 |
CVE-2024-13357 |
WPScan | |
| 6.8 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 2.5.1 Fixed in 2.5.1 |
CVE-2025-3742 |
WPScan | |
| 5.3 Medium | Responsive Plus | Broken Access Control No login needed |
≤ 3.1.9 Fixed in 3.2.0 |
CVE-2025-47486 |
Patchstack | |
| 4.3 Medium | Simple Sitemap – Create a Responsive HTML Sitemap | Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2025-39413 |
Patchstack | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.2 Fixed in 2.0.3 |
CVE-2025-39578 |
Patchstack | |
| 6.4 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rael_title_tag' |
≤ 1.6.9 |
CVE-2025-2225 |
Wordfence | |
| 4.3 Medium | Freetobook Responsive Widget | Cross-Site Request Forgery No login needed |
≤ 1.1 Fixed in 1.1.1 |
CVE-2025-32273 |
Patchstack | |
| 6.5 Medium | Lightweight and Responsive Youtube Embed | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2025-31744 |
Patchstack | |
| 6.5 Medium | Lightweight and Responsive Youtube Embed | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2025-31743 |
Patchstack | |
| 5.7 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Information Disclosure Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure |
≤ 1.6.8 |
CVE-2025-2228 |
Wordfence | |
| 4.9 Medium | Thumbnail carousel slider | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.4 |
CVE-2019-25222 |
Wordfence | |
| 5.3 Medium | Responsive Google Map | Broken Access Control No login needed |
≤ 3.1.5 |
CVE-2025-28920 |
Patchstack | |
| 4.3 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates |
≤ 2.4.29 |
CVE-2024-12114 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size |
≤ 2.4.29 |
CVE-2024-12119 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode |
≤ 3.10.7 |
CVE-2024-11731 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.16.5 |
CVE-2024-13778 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library |
≤ 1.3.4, ≤ 2.4.7 |
CVE-2024-5667 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode |
≤ 3.10.6 |
CVE-2024-13757 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion |
≤ 1.16.5 |
CVE-2024-13780 |
Wordfence | |
| 6.1 Medium | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-13779 |
Wordfence | |
| 5.1 Medium | FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed |
2.4.29 |
CVE-2025-22624 |
Fluid Attacks | |
| 6.5 Medium | WP Responsive Auto Fit Text | Cross-Site Scripting |
≤ 0.2 Fixed in 0.3 |
CVE-2025-26904 |
Patchstack | |
| 6.4 Medium | Responsive Flickr Slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13660 |
Wordfence | |
| 5.4 Medium | Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive | Server-Side Request Forgery Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_request |
≤ 3.1.4 |
CVE-2024-13834 |
Wordfence | |
| 6.5 Medium | Aparat Responsive | Cross-Site Scripting |
≤ 1.3 |
CVE-2025-26558 |
Patchstack | |
| 5.4 Medium | Global Gallery - WordPress Responsive Gallery | Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 9.1.5 |
CVE-2024-13814 |
Wordfence | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 1.9.9 Fixed in 2.0.0 |
CVE-2025-22697 |
Patchstack | |
| 6.5 Medium | Image Gallery – Responsive Photo Gallery | Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed |
≤ 1.0.5 Fixed in 1.2 |
CVE-2025-24697 |
Patchstack | |
| 5.4 Medium | Responsive iframe | Cross-Site Scripting Contributor+ Stored XSS |
≤ 1.2.0 |
CVE-2024-12768 |
WPScan | |
| 6.4 Medium | Responsive Blocks – WordPress Gutenberg Blocks | Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter |
≤ 1.9.9 |
CVE-2024-13732 |
Wordfence | |
| 5.4 Medium | Responsive Slider by MetaSlider | Cross-Site Request Forgery No login needed |
≤ 3.92.0 Fixed in 3.92.1 |
CVE-2025-24533 |
Patchstack | |
| 6.4 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.4 |
CVE-2024-13354 |
Wordfence | |
| 4.3 Medium | AI Responsive Gallery Album | Broken Access Control |
≤ 1.4 |
CVE-2025-23785 |
Patchstack | |
| 6.4 Medium | WP Responsive Tabs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.9 |
CVE-2024-13387 |
Wordfence | |
| 6.5 Medium | Responsive jQuery Slider | Cross-Site Scripting |
≤ 1.1.1 |
CVE-2025-22798 |
Patchstack | |
| 6.1 Medium | Image Gallery – Responsive Photo Gallery | Cross-Site Scripting Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.0.5 |
CVE-2024-12403 |
Wordfence | |
| 6.5 Medium | Responsive Flickr Slideshow | Cross-Site Scripting |
≤ 2.6.0 Fixed in 2.6.1 |
CVE-2025-22807 |
Patchstack | |
| 6.4 Medium | Responsive FlipBook Plugin | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.5.0 |
CVE-2024-11929 |
Wordfence | |
| 6.4 Medium | Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11382 |
Wordfence | |
| 4.3 Medium | Photo Gallery Slideshow & Masonry Tiled Gallery | Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery |
≤ 1.0.15 |
CVE-2024-12237 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.