WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 101–150 of 343 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Image Gallery – Photo Grid & Video Gallery (Modula) Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing ≤ 2.13.3 CVE-2025-13891 Wordfence
4.3 Medium Vimeo SimpleGallery Plugin vimeo-simplegallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification ≤ 0.2 CVE-2025-14170 Wordfence
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting ≤ 3.3.2.1 Fixed in 3.3.2.2 CVE-2025-63052 Patchstack
6.5 Medium JNews Gallery Plugin jnews-gallery Cross-Site Scripting ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67538 Patchstack
6.4 Medium Social Feed Gallery Portfolio Plugin social-feed-gallery-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.3 CVE-2025-13896 Wordfence
6.1 Medium dream gallery Plugin dream-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed ≤ 1.0 CVE-2025-13621 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.4 Medium Multiple Plugins and Themes <= (Various Versions) Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library ≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … CVE-2025-5092 Wordfence
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 2.5.3 CVE-2025-12359 Wordfence
6.4 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Caption Attribute ≤ 3.21 CVE-2025-12691 Wordfence
5.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control Missing Authorization No login needed ≤ 28.0.2 CVE-2025-12849 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Arbitrary File Deletion Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move ≤ 2.12.28 CVE-2025-12494 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions ≤ 1.12.0 CVE-2025-12377 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion ≤ 1.11.0 CVE-2025-11448 Wordfence
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
6.5 Medium Video Gallery by Huzzaz Plugin huzzaz-video-gallery Cross-Site Scripting ≤ 10.5 CVE-2025-62910 Patchstack
5.3 Medium Social Feed Gallery Plugin insta-gallery Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 4.9.2 CVE-2025-10637 Wordfence
6.4 Medium WP AD Gallery Plugin wp-ad-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2025-11834 Wordfence
4.3 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Content Injection Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection No login needed ≤ 27.0.3 CVE-2025-11254 Wordfence
6.3 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-9710 WPScan
6.4 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 27.0.2 CVE-2025-10383 Wordfence
6.5 Medium Woo superb slideshow transition gallery with random effect Plugin woo-superb-slideshow-transition-gallery-with-random-effect SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.1 CVE-2025-9199 Wordfence
5.9 Medium Gallery Custom Links Plugin gallery-custom-links Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-60104 Patchstack
6.5 Medium Fusion Page Builder : Extension – Gallery Plugin fusion-extension-gallery Cross-Site Scripting Gallery Plugin <= 1.7.6 - Cross Site Scripting (XSS) ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-58965 Patchstack
6.5 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting ≤ 6.3.8 Fixed in 6.3.9 CVE-2025-57947 Patchstack
6.5 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.41 Fixed in 1.0.0.43 CVE-2025-57966 Patchstack
5.9 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Scripting ≤ 1.5.5 CVE-2025-57974 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure No login needed ≤ 1.16.16 Fixed in 1.16.17 CVE-2025-58226 Patchstack
6.4 Medium Easy Social Feed – Social Photos Gallery – Post Feed – Like Box Plugin easy-facebook-likebox Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.6.7 CVE-2025-6067 Wordfence
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-58610 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' ≤ 6.2.2 CVE-2025-8451 Wordfence
4.3 Medium flexo-social-gallery Plugin flexo-social-gallery Cross-Site Request Forgery No login needed ≤ 1.0006 CVE-2025-52769 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.2.0.2 Fixed in 2.2.0.3 CVE-2025-54749 Patchstack
6.5 Medium Global Gallery Plugin global-gallery Broken Access Control No login needed ≤ 9.2.3 Fixed in 9.2.4 CVE-2025-52721 Patchstack
6.1 Medium Image Gallery Plugin bee-quick-gallery Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-8400 Wordfence
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
6.4 Medium Vertical scroll image slideshow gallery Plugin vertical-scroll-image-slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 11.1 CVE-2025-5752 Wordfence
4.3 Medium Block Editor Gallery Slider Plugin block-editor-gallery-slider Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update ≤ 1.1.1 CVE-2025-6726 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 CVE-2025-6068 Wordfence
6.4 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 26.0.8 CVE-2025-6716 Wordfence
6.5 Medium Video Gallery Block Plugin video-gallery-block Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-27326 Patchstack
6.4 Medium Portfolio for Elementor & Image Gallery | PowerFolio Plugin portfolio-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.2.0 CVE-2025-7046 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library ≤ 2.6.7, ≤ 3.5, ≤ 3.59.11 CVE-2025-2537 Wordfence
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Contributor+ Stored XSS < 2.5.2 Fixed in 2.5.2 CVE-2025-5093 WPScan
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
6.5 Medium YouTube Simple Gallery Plugin youtube-simple-gallery Cross-Site Scripting ≤ 2.2.0 CVE-2025-29011 Patchstack
6.4 Medium Paged Gallery Plugin paged-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.7 CVE-2025-5686 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library ≤ 2.14.4, ≤ 3.59.4 CVE-2024-5878 Wordfence
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.29 Fixed in 1.8.29 CVE-2024-8670 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only