WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 51–100 of 161 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Slide Puzzle Plugin slide-puzzle Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-52751 Patchstack
7.1 High Fade Slider Plugin fade-slider Cross-Site Scripting No login needed ≤ 2.5 Fixed in 2.6 CVE-2025-49956 Patchstack
7.1 High WP Smart Flexslider Plugin wp-smart-flexslider Cross-Site Scripting No login needed ≤ 2.5 CVE-2025-49955 Patchstack
7.5 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion ≤ 2.1.7 CVE-2025-32657 Patchstack
8.8 High AP Background Plugin ap-background Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload via advParallaxBackAdminSaveSlider Function 3.8.1 – 3.8.2 CVE-2025-9561 Wordfence
8.8 High Testimonial Slider Plugin testimonial-add Local File Inclusion ≤ 3.5.8.6 CVE-2025-60126 Patchstack
8.5 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider SQL Injection AllInOne - Content Slider Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60109 Patchstack
7.1 High HORIZONTAL SLIDER Plugin horizontal-slider Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-58676 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-48154 Patchstack
7.1 High Youtube Vimeo Video Player and Slider WP Plugin video-player-youtube-vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-48159 Patchstack
7.1 High Youtube Vimeo Video Player and Slider Plugin video_player_youtube_vimeo Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.9 CVE-2025-53563 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-30626 Patchstack
8.8 High B Slider- Gutenberg Slider Block for WP Plugin b-slider Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation ≤ 1.1.30 CVE-2025-8418 Wordfence
8.8 High Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload < 1.0.1 Fixed in 1.0.1 CVE-2015-10144 Wordfence
8.5 High Pixelating image slideshow gallery Plugin pixelating-image-slideshow-gallery SQL Injection ≤ 8.0 CVE-2025-30979 Patchstack
7.1 High Image Slider With Description Plugin image-slider-with-description Cross-Site Request Forgery No login needed ≤ 9.2 CVE-2025-53308 Patchstack
7.5 High WPB Category Slider for WooCommerce Plugin wpb-woocommerce-category-slider Local File Inclusion ≤ 1.71 CVE-2025-53281 Patchstack
7.1 High Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.8.4 Fixed in 0.5.8.5 CVE-2025-49290 Patchstack
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
7.1 High Recent Posts Slider Responsive Plugin recent-posts-slider-responsive Cross-Site Request Forgery No login needed ≤ 1.0.1 CVE-2025-28966 Patchstack
7.1 High Theme Blvd Sliders Plugin theme-blvd-sliders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-46456 Patchstack
7.5 High Product Category Slider for WooCommerce Plugin woo-category-slider-by-pluginever Local File Inclusion ≤ 4.3.4 Fixed in 4.3.5 CVE-2025-39364 Patchstack
8.5 High UberSlider Plugin uber-classic SQL Injection ≤ 2.6 Fixed in 2.6 CVE-2025-31641 Patchstack
8.5 High Magic Responsive Slider and Carousel Plugin magic-carousel SQL Injection ≤ 1.6 Fixed in 1.6 CVE-2025-31640 Patchstack
7.5 High Slider & Popup Builder by Depicter Plugin depicter SQL Injection Unauthenticated SQL Injection via 's' Parameter No login needed ≤ 3.6.1 CVE-2025-2011 Wordfence
7.1 High visualslider Sldier Plugin visual-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.4 CVE-2025-23448 Patchstack
7.1 High flickr-slideshow-wrapper Plugin flickr-slideshow-wrapper Cross-Site Scripting No login needed ≤ 5.4.6 CVE-2025-27309 Patchstack
7.1 High T&P Gallery Slider Plugin tp-gallery-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-32527 Patchstack
7.1 High GB Gallery Slideshow Plugin gb-gallery-slideshow Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-32649 Patchstack
7.1 High ZooEffect Plugin 1-jquery-photo-gallery-slideshow-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.11 CVE-2025-26954 Patchstack
8.1 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion No login needed ≤ 2.3.15 CVE-2025-32656 Patchstack
7.1 High Smart Product Gallery Slider Plugin smart-product-gallery-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.4 CVE-2025-31392 Patchstack
7.5 High Slider a SlidersPack Plugin sliderspack-all-in-one-image-sliders Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2025-32152 Patchstack
8.8 High Testimonial Slider Plugin testimonial PHP Object Injection ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-30889 Patchstack
7.1 High The Logo Slider Plugin the-logo-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-31571 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30589 Patchstack
7.1 High wordpress related Posts with thumbnails Plugin related-posts-list-grid-and-slider-all-in-one Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0.1 CVE-2025-31569 Patchstack
8.8 High SoJ Soundslides Plugin soj-soundslides Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2.2 CVE-2025-2249 Wordfence
7.1 High SUPER RESPONSIVE SLIDER Plugin super-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22575 Patchstack
7.1 High ShowTime Slideshow Plugin showtime-slideshow Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.6 CVE-2025-31444 Patchstack
7.6 High Slider by BestWebSoft Plugin slider-bws SQL Injection ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-31099 Patchstack
8.2 High WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 16.0 Fixed in 16.1 CVE-2025-30783 Patchstack
7.1 High WP Simple Slideshow Plugin wp-simple-slideshow Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26576 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30590 Patchstack
7.3 High Logo Slider Plugin gs-logo-slider Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.7.3 CVE-2025-2262 Wordfence
7.1 High Ui Slider Filter By Price Plugin ui-slider-filter-by-price Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23555 Patchstack
7.1 High Flexo Slider Plugin flexo-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0013 CVE-2025-23472 Patchstack
7.1 High Smooth Dynamic Slider Plugin smooth-dynamic-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23447 Patchstack
7.6 High WP Yelp Review Slider Plugin wp-yelp-review-slider SQL Injection ≤ 8.1 Fixed in 8.2 CVE-2025-26946 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only