WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 101–150 of 161 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High WP Airbnb Review Slider Plugin wp-airbnb-review-slider SQL Injection ≤ 3.9 Fixed in 4.0 CVE-2025-26755 Patchstack
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
7.1 High FWD Slider Plugin fwd-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23462 Patchstack
7.1 High Cyber Slider Plugin cyber-new-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23630 Patchstack
7.1 High Len Slider Plugin len-slider Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 CVE-2025-23810 Patchstack
7.1 High Slider for Writers Plugin slider-for-writers Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-23692 Patchstack
7.1 High NV Slider Plugin nv-slider Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-23661 Patchstack
7.1 High Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-22750 Patchstack
7.1 High MG Parallax Slider Plugin mg-parallax-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0. CVE-2025-22330 Patchstack
7.1 High Smoothness Slider Shortcode Plugin smoothness-slider-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ v1.2.2 CVE-2025-22555 Patchstack
7.1 High Gulri Slider Plugin gulri-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2024-56223 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
7.5 High Easing Slider Plugin easing-slider Broken Access Control Plugin Settings Reset No login needed ≤ 3.0.8 CVE-2023-30490 Patchstack
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
8.8 High Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Local File Inclusion Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion ≤ 3.3.3 CVE-2024-11429 Wordfence
7.1 High Infinite Slider Plugin infinite-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-52461 Patchstack
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
7.1 High SH Slideshow Plugin sh-slideshow Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.3 CVE-2024-51632 Patchstack
7.3 High Uix Slideshow Plugin uix-slideshow Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.5 CVE-2024-9839 Wordfence
7.1 High Wp Slide Categorywise Plugin wp-slide-categorywise Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51690 Patchstack
7.1 High Team Showcase and Slider – Team Members Builder Plugin team-showcase-ultimate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51763 Patchstack
7.1 High Banner Slider Plugin banner-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2024-49635 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
7.1 High All in One Slider Plugin all-in-one-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-49323 Patchstack
7.1 High jLayer Parallax Slider Plugin jlayer-parallax-slider-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49334 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.6 High Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-5429 WPScan
7.5 High MaxSlider Plugin maxslider Local File Inclusion ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-47351 Patchstack
7.1 High Product Slider for WooCommerce Plugin woocommerce-products-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.50 Fixed in 1.13.51 CVE-2024-45459 Patchstack
8.5 High Timeline and History slider Plugin timeline-and-history-slider Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43232 Patchstack
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
8.8 High Depicter — Popup & Slider Builder Plugin depicter Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload ≤ 3.1.1 CVE-2024-4389 Wordfence
8.8 High Slider by 10Web – Responsive Image Slider Plugin slider-wd SQL Injection Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.2.57 CVE-2024-7150 Wordfence
7.1 High Simple Responsive Slider Plugin simple-responsive-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.2.5 CVE-2024-37954 Patchstack
7.1 High Master Slider Plugin master-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.5 CVE-2024-37222 Patchstack
7.1 High Slider Revolution Plugin Broken Access Control Unauthenticated Broken Access Control No login needed < 6.7.0 Fixed in 6.7.0 CVE-2024-34444 Patchstack
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
8.1 High Slideshow Gallery LITE Plugin slideshow-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.8.1 CVE-2024-5543 Wordfence
7.4 High SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets ≤ 2.0 CVE-2024-5091 Wordfence
7.6 High WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection ≤ 12.6 Fixed in 12.7 CVE-2024-35630 Patchstack
8.8 High Ditty – Responsive News Tickers, Sliders, and Lists Plugin ditty-news-ticker PHP Object Injection Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection ≤ 3.1.38 CVE-2024-3954 Wordfence
7.7 High Rolo Slider Plugin rolo-slider Broken Access Control ≤ 1.0.9 CVE-2024-1438 Patchstack
7.1 High Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32682 Patchstack
8.3 High Master Slider Plugin master-slider PHP Object Injection No login needed ≤ 3.9.5 Fixed in 3.9.7 CVE-2024-32600 Patchstack
7.1 High Slider by 10Web Plugin slider-wd Cross-Site Scripting No login needed ≤ 1.2.54 Fixed in 1.2.55 CVE-2024-32578 Patchstack
8.5 High Slideshow Gallery Plugin slideshow-gallery SQL Injection Auth. SQL Injection ≤ 1.7.8 CVE-2024-31355 Patchstack
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only