WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 101–143 of 143 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.24 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.24 Fixed in 2.7.7.25 CVE-2025-24707 Patchstack
7.1 High FooGallery Captions Plugin foogallery-captions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23889 Patchstack
7.1 High Good Old Gallery Plugin good-old-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-23959 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
7.1 High Gallery Plugin wordpress-gallery-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23842 Patchstack
7.1 High Photo Gallery – Image Gallery by Ape Plugin gallery-images-ape Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.8 CVE-2025-22317 Patchstack
8.8 High Modula Image Gallery Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.11.10 CVE-2024-12853 Wordfence
7.1 High BVD Easy Gallery Manager Plugin bvd-easy-gallery-manager Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-22353 Patchstack
7.1 High odPhotogallery Plugin od-photogallery-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.3 CVE-2024-56036 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
7.5 High Video Gallery – YouTube Gallery Plugin gallery-videos Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2023-25988 Patchstack
7.7 High Best WordPress Gallery Plugin – FooGallery Plugin Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.26 CVE-2023-6947 Wordfence
8.8 High Gallery Plugin multi-gallery PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.3 CVE-2024-11501 Wordfence
7.2 High YouTube Gallery and Vimeo Gallery Plugin gallery-videos SQL Injection Authenticated (Administrator+) SQL Injection ≤ 2.4.2 CVE-2024-10247 Wordfence
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
7.2 High Grid View Gallery Plugin grid-view-gallery PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 1.0 CVE-2024-11409 Wordfence
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
8.5 High Easy Gallery Plugin simple-gallery-odihost SQL Injection ≤ 1.4 CVE-2024-51570 Patchstack
7.1 High CWD 3D Image Gallery Plugin cwd-3d-image-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49632 Patchstack
8.8 High WP Easy Gallery Plugin wp-easy-gallery SQL Injection Authenticated (Contributor+) SQL Injection via key Parameter ≤ 4.8.5 CVE-2024-9018 Wordfence
8.5 High Unite Gallery Lite Plugin unite-gallery-lite SQL Injection ≤ 1.7.62 CVE-2024-43207 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-39631 Patchstack
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
8.8 High Photo Video Gallery Master Plugin photo-video-gallery-master PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.5.3 CVE-2024-5724 Wordfence
8.1 High Slideshow Gallery LITE Plugin slideshow-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.8.1 CVE-2024-5543 Wordfence
8.5 High Contest Gallery Plugin contest-gallery Arbitrary File Deletion ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-32778 Patchstack
8.5 High Responsive Image Gallery, Gallery Album Plugin gallery-album SQL Injection Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 CVE-2024-35750 Patchstack
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode ≤ 3.6.5 CVE-2024-4670 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via featured image ≤ 3.6.4 CVE-2024-4033 Wordfence
7.5 High Grid Gallery – Photo Image Grid Gallery Plugin new-grid-gallery PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode ≤ 1.4.3 CVE-2024-1897 Wordfence
7.5 High Photo Gallery Plugin new-photo-gallery PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode ≤ 1.4.2 CVE-2024-1896 Wordfence
8.8 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode ≤ 4.6.18 CVE-2024-3293 Wordfence
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.21 Fixed in 1.8.22 CVE-2024-32583 Patchstack
8.5 High Slideshow Gallery Plugin slideshow-gallery SQL Injection Auth. SQL Injection ≤ 1.7.8 CVE-2024-31355 Patchstack
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-30428 Patchstack
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-30236 Patchstack
8.5 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 21.3.2 Fixed in 21.3.2.1 CVE-2024-30238 Patchstack
7.1 High Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.2 Fixed in 5.5.3 CVE-2024-29919 Patchstack
8.8 High Vimeography: Vimeo Video Gallery Plugin vimeography PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.3.2 CVE-2024-0825 Wordfence
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1859 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only