WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 251 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | Kiamo - Responsive Business Service | Local File Inclusion Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion No login needed |
≤ 1.3.3 |
CVE-2025-31633 |
Patchstack | |
| 9.8 Critical | Madara – Responsive and modern WordPress theme for manga sites | Local File Inclusion Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion No login needed |
≤ 2.2.2 |
CVE-2025-4524 |
Wordfence | |
| 8.5 High | Magic Responsive Slider and Carousel | SQL Injection |
≤ 1.6 Fixed in 1.6 |
CVE-2025-31640 |
Patchstack | |
| 8.5 High | Multimedia Responsive Carousel with Image Video Audio Support | SQL Injection |
≤ 2.6.0 Fixed in 2.6.1 |
CVE-2025-31928 |
Patchstack | |
| 8.5 High | Responsive HTML5 Audio Player PRO With Playlist | SQL Injection |
≤ 3.5.7 |
CVE-2025-32287 |
Patchstack | |
| 3.5 Low | Responsive Gallery Grid | Cross-Site Scripting Admin+ Stored XSS |
< 2.3.15 Fixed in 2.3.15 |
CVE-2024-4091 |
WPScan | |
| 4.8 Medium | Ditty – Responsive News Tickers, Sliders, and Lists | Cross-Site Scripting Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS |
< 3.1.52 Fixed in 3.1.52 |
CVE-2024-13357 |
WPScan | |
| 6.8 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 2.5.1 Fixed in 2.5.1 |
CVE-2025-3742 |
WPScan | |
| 5.3 Medium | Responsive Plus | Broken Access Control No login needed |
≤ 3.1.9 Fixed in 3.2.0 |
CVE-2025-47486 |
Patchstack | |
| 4.3 Medium | Simple Sitemap – Create a Responsive HTML Sitemap | Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2025-39413 |
Patchstack | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 2.0.2 Fixed in 2.0.3 |
CVE-2025-39578 |
Patchstack | |
| 6.4 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rael_title_tag' |
≤ 1.6.9 |
CVE-2025-2225 |
Wordfence | |
| 4.3 Medium | Freetobook Responsive Widget | Cross-Site Request Forgery No login needed |
≤ 1.1 Fixed in 1.1.1 |
CVE-2025-32273 |
Patchstack | |
| 6.5 Medium | Lightweight and Responsive Youtube Embed | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2025-31744 |
Patchstack | |
| 6.5 Medium | Lightweight and Responsive Youtube Embed | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2025-31743 |
Patchstack | |
| 7.1 High | SUPER RESPONSIVE SLIDER | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2025-22575 |
Patchstack | |
| 5.7 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Information Disclosure Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure |
≤ 1.6.8 |
CVE-2025-2228 |
Wordfence | |
| 4.9 Medium | Thumbnail carousel slider | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.4 |
CVE-2019-25222 |
Wordfence | |
| 8.8 High | JobCareer | Job Board Responsive | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions |
≤ 7.1 |
CVE-2024-12810 |
Wordfence | |
| 5.3 Medium | Responsive Google Map | Broken Access Control No login needed |
≤ 3.1.5 |
CVE-2025-28920 |
Patchstack | |
| 4.3 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates |
≤ 2.4.29 |
CVE-2024-12114 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size |
≤ 2.4.29 |
CVE-2024-12119 |
Wordfence | |
| 8.1 High | Flex Mag - Responsive WordPress News | Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion |
≤ 3.5.2 |
CVE-2024-13655 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode |
≤ 3.10.7 |
CVE-2024-11731 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | SQL Injection Responsive WordPress Menu Plugin <= 1.16.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.16.5 |
CVE-2024-13778 |
Wordfence | |
| 6.4 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library |
≤ 1.3.4, ≤ 2.4.7 |
CVE-2024-5667 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode |
≤ 3.10.6 |
CVE-2024-13757 |
Wordfence | |
| 6.5 Medium | Hero Mega Menu - Responsive WordPress Menu | Broken Access Control Responsive WordPress Menu Plugin <= 1.16.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Directory Deletion |
≤ 1.16.5 |
CVE-2024-13780 |
Wordfence | |
| 6.1 Medium | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting Responsive WordPress Menu Plugin <= 1.16.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-13779 |
Wordfence | |
| 5.1 Medium | FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed |
2.4.29 |
CVE-2025-22624 |
Fluid Attacks | |
| 8.8 High | Car Dealer Automotive WordPress Theme – Responsive | Arbitrary File Deletion Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read |
≤ 1.6.3 |
CVE-2025-1282 |
Wordfence | |
| 6.5 Medium | WP Responsive Auto Fit Text | Cross-Site Scripting |
≤ 0.2 Fixed in 0.3 |
CVE-2025-26904 |
Patchstack | |
| 8.8 High | Photo Gallery ( Responsive ) | Cross-Site Request Forgery CSRF to Privilege Escalation No login needed |
≤ 4.0 |
CVE-2025-27276 |
Patchstack | |
| 7.1 High | Responsive Modal Builder for High Conversion – Easy Popups | Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed |
≤ 1.5.0 Fixed in 1.5.1 |
CVE-2025-26774 |
Patchstack | |
| 9.8 Critical | Responsive Slider by MetaSlider | PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed |
≤ 3.94.0 Fixed in 3.95.0 |
CVE-2025-26763 |
Patchstack | |
| 8.8 High | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Local File Inclusion Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.6.4 |
CVE-2024-13353 |
Wordfence | |
| 6.4 Medium | Responsive Flickr Slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13660 |
Wordfence | |
| 5.4 Medium | Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive | Server-Side Request Forgery Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_request |
≤ 3.1.4 |
CVE-2024-13834 |
Wordfence | |
| 6.5 Medium | Aparat Responsive | Cross-Site Scripting |
≤ 1.3 |
CVE-2025-26558 |
Patchstack | |
| 7.1 High | Simple Responsive Menu | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.1 |
CVE-2025-26543 |
Patchstack | |
| 5.4 Medium | Global Gallery - WordPress Responsive Gallery | Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 9.1.5 |
CVE-2024-13814 |
Wordfence | |
| 6.5 Medium | Responsive Blocks | Cross-Site Scripting |
≤ 1.9.9 Fixed in 2.0.0 |
CVE-2025-22697 |
Patchstack | |
| 6.5 Medium | Image Gallery – Responsive Photo Gallery | Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed |
≤ 1.0.5 Fixed in 1.2 |
CVE-2025-24697 |
Patchstack | |
| 5.4 Medium | Responsive iframe | Cross-Site Scripting Contributor+ Stored XSS |
≤ 1.2.0 |
CVE-2024-12768 |
WPScan | |
| 6.4 Medium | Responsive Blocks – WordPress Gutenberg Blocks | Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter |
≤ 1.9.9 |
CVE-2024-13732 |
Wordfence | |
| 5.4 Medium | Responsive Slider by MetaSlider | Cross-Site Request Forgery No login needed |
≤ 3.92.0 Fixed in 3.92.1 |
CVE-2025-24533 |
Patchstack | |
| 6.4 Medium | Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | Cross-Site Scripting Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.4 |
CVE-2024-13354 |
Wordfence | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49333 |
Patchstack | |
| 8.5 High | Hero Mega Menu - Responsive WordPress Menu | SQL Injection |
≤ 1.16.5 |
CVE-2024-49303 |
Patchstack | |
| 7.1 High | Hero Mega Menu - Responsive WordPress Menu | Cross-Site Scripting No login needed |
≤ 1.16.5 |
CVE-2024-49300 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.