WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–100 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical Responsive Slider by MetaSlider Plugin ml-slider Remote Code Execution ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39465 Patchstack
6.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Scripting No login needed ≤ 18.0 Fixed in 18.1 CVE-2026-39451 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
6.5 Medium Slider Revolution Plugin Information Disclosure Authenticated (Subscriber+) Sensitive Information Disclosure 7.0 – 7.0.10 CVE-2026-7542 Wordfence
4.9 Medium Smart Slider 3 Plugin smart-slider-3 Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export ≤ 3.5.1.36 CVE-2026-9197 Wordfence
6.4 Medium Simple SEO Slideshow Plugin simple-seo-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.2.8 CVE-2026-8900 Wordfence
10.0 Critical Product Slider Pro for WooCommerce Plugin woo-product-slider-pro Other Backdoor No login needed < 3.5.4 Fixed in 3.5.4 CVE-2026-49777 Patchstack
8.2 High Google Review Slider Plugin wp-google-places-review-slider SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed 6.1 CVE-2019-25745 VulnCheck
4.3 Medium Slider Revolution Plugin Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure 7.0.0 – 7.0.14 CVE-2026-9048 Wordfence
4.3 Medium Slider Revolution 6.0.0-6.7.55 and Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation 6.0.0 – 6.7.55, 7.0.0 – 7.0.14 CVE-2026-9050 Wordfence
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.10.8 Fixed in 3.10.9 CVE-2026-48968 Patchstack
6.4 Medium Content Slideshow Plugin content-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 2.4.1 CVE-2026-8873 Wordfence
6.4 Medium jQuery googleslides Plugin jquery-googleslides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.3 CVE-2026-8866 Wordfence
4.3 Medium Slider by Soliloquy Plugin soliloquy-lite Information Disclosure Authenticated (Subscriber+) Information Disclosure via REST API Endpoint ≤ 2.8.1 CVE-2026-7636 Wordfence
5.3 Medium Slider Revolution Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via 'sliders/stream' No login needed 6.0 – 6.7.54, 7.0 – 7.0.9 CVE-2026-6728 Wordfence
4.3 Medium Photo Gallery, Sliders, Proofing and Themes Plugin nextgen-gallery Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API ≤ 4.2.0 CVE-2026-6566 Wordfence
8.8 High HS Brand Logo Slider Plugin hs-brand-logo-slider Arbitrary File Upload WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload 2.1 CVE-2020-37227 VulnCheck
6.4 Medium Slider by Soliloquy Plugin soliloquy-lite Cross-Site Scripting WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS 2.6.2 CVE-2021-47922 VulnCheck
6.4 Medium Testimonial Slider and Showcase Plugin testimonial-slider-and-showcase Cross-Site Scripting WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS 2.2.6 CVE-2022-50947 VulnCheck
5.9 Medium WEN Logo Slider Plugin wen-logo-slider Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5 CVE-2025-62127 Patchstack
8.8 High Slider Revolution Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url 7.0.0 – 7.0.10 CVE-2026-6692 Wordfence
6.4 Medium Gutentools Plugin gutentools Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes ≤ 1.1.3 CVE-2026-1395 Wordfence
6.4 Medium SlideShowPro SC Plugin slideshowpro-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'album' Shortcode Attribute ≤ 1.0.2 CVE-2026-5767 Wordfence
6.4 Medium Slider Bootstrap Carousel Plugin slider-bootstrap-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.7 CVE-2026-4076 Wordfence
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
7.2 High Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.1.5 CVE-2026-5694 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
9.8 Critical Smart Slider 3 Pro Plugin nextend-smart-slider3-pro Remote Code Execution Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit No login needed 3.5.1.35 Fixed in 3.5.1.36 CVE-2026-34424 VulnCheck
6.4 Medium Post Blocks & Tools Plugin bnm-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'sliderStyle' Block Attribute ≤ 1.3.0 CVE-2026-5711 Wordfence
6.4 Medium Prime Slider Plugin bdthemes-prime-slider-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_text' Parameter ≤ 4.1.10 CVE-2026-4341 Wordfence
5.4 Medium Smart Slider 3 Plugin smart-slider-3 Broken Access Control Missing Authorization to Authenticated (Contributor+) Slider Data Read and Image Record Manipulation ≤ 3.5.1.33 CVE-2026-4065 Wordfence
6.5 Medium Smart Slider 3 Plugin smart-slider-3 Path Traversal Authenticated (Subscriber+) Arbitrary File Read via actionExportAll ≤ 3.5.1.33 CVE-2026-3098 Wordfence
7.1 High Image Slider by Ays Plugin ays-slider Cross-Site Scripting No login needed ≤ <= 2.7.1 Fixed in 2.7.2 CVE-2026-32494 Patchstack
6.5 Medium WP Review Slider Plugin wp-facebook-reviews Cross-Site Scripting ≤ <= 13.9 Fixed in 14.0 CVE-2026-32491 Patchstack
6.5 Medium WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider Cross-Site Scripting ≤ <= 14.1 Fixed in 14.2 CVE-2026-32490 Patchstack
6.5 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control ≤ 1.13.61 Fixed in 1.13.62 CVE-2026-25455 Patchstack
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `Fancy Text Widget` And `Countdown Widget` ≤ 3.7.0 CVE-2025-6229 Wordfence
6.4 Medium Logo Slider Plugin logo-slider-wp Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortcode ≤ 4.9.0 CVE-2026-0609 Wordfence
6.4 Medium Multi Post Carousel by Category Plugin multi-post-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'slides' Shortcode Attribute ≤ 1.4 CVE-2026-1275 Wordfence
4.3 Medium Lobot Slider Administrator Plugin lobot-slider-administrator Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 0.6.0 CVE-2026-3331 Wordfence
6.4 Medium Any Post Slider Plugin any-post-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_type' Shortcode Attribute ≤ 1.0.4 CVE-2026-1899 Wordfence
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion ≤ 4.0.4 CVE-2026-1463 Wordfence
5.3 Medium Image Slider by Ays Plugin ays-slider Broken Access Control No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-32402 Patchstack
7.1 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider Cross-Site Scripting AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8 CVE-2026-28109 Patchstack
7.1 High LBG Zoominoutslider Plugin lbg_zoominoutslider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.5 CVE-2026-28103 Patchstack
7.1 High UberSlider Classic Plugin uberslider_classic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 CVE-2026-28102 Patchstack
7.1 High UberSlider MouseInteraction Plugin uberslider_mouseinteraction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28101 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only