WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 101–150 of 383 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Quick Interest Slider Plugin quick-interest-slider Broken Access Control No login needed ≤ 3.1.7 CVE-2025-62153 Patchstack
6.4 Medium Soundslides Plugin soundslides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundslides Shortcode ≤ 1.4.2 CVE-2025-12713 Wordfence
6.5 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting ≤ 1.9.13 Fixed in 1.9.14 CVE-2025-66092 Patchstack
5.4 Medium WP Google Review Slider Plugin wp-google-places-review-slider Broken Access Control ≤ 17.4 Fixed in 17.6 CVE-2025-66063 Patchstack
6.1 Medium YSlider Plugin yslider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-12590 Wordfence
5.4 Medium Slippy Slider – Responsive Touch Navigation Slider Plugin slippy-slider-responsive-touch-navigation-slider Cross-Site Scripting Responsive Touch Navigation Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-11874 Wordfence
4.0 Medium WP Airbnb Review Slider Plugin wp-airbnb-review-slider Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.2 CVE-2025-12520 Wordfence
4.3 Medium Depicter — Popup & Slider Builder Plugin depicter Broken Access Control Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload ≤ 4.0.4 CVE-2025-11373 Wordfence
4.9 Medium Easy Testimonial Slider and Form Plugin easy-testimonial-rotator SQL Injection Authenticated (Admin+) SQL injection ≤ 1.0.2 CVE-2015-10147 Wordfence
4.9 Medium Thumbnail Slider With Lightbox Plugin wp-responsive-slider-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2015-10146 Wordfence
4.9 Medium Slider Templates Plugin slider-templates Server-Side Request Forgery ≤ 1.0.3 CVE-2025-62988 Patchstack
6.5 Medium Testimonial Slider Plugin testimonial Broken Access Control ≤ 2.0.15 CVE-2025-62929 Patchstack
4.3 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Request Forgery No login needed ≤ 0.5.8.5 Fixed in 0.5.9 CVE-2025-62891 Patchstack
6.1 Medium Multi Item Responsive Slider Plugin mislider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-11992 Wordfence
6.5 Medium Slider Revolution Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Read ≤ 6.7.37 CVE-2025-10249 Wordfence
6.5 Medium Woo superb slideshow transition gallery with random effect Plugin woo-superb-slideshow-transition-gallery-with-random-effect SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.1 CVE-2025-9199 Wordfence
6.4 Medium Ird Slider Plugin ird-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-9876 Wordfence
5.9 Medium PE Easy Slider Plugin pe-easy-slider Cross-Site Scripting ≤ 1.1.0 CVE-2025-60133 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control ≤ 1.7.0 CVE-2025-57955 Patchstack
6.5 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.41 Fixed in 1.0.0.43 CVE-2025-57966 Patchstack
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.11.0 CVE-2025-58025 Patchstack
6.1 Medium Side Slide Responsive Menu Plugin side-slide-responsive-menu Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9880 Wordfence
4.3 Medium Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid Plugin blog-designer-for-elementor Cross-Site Request Forgery Post Slider, Post Carousel, Post Grid <= 1.1.7 - Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-8481 Wordfence
6.5 Medium Simple Text Slider Plugin simple-text-slider Cross-Site Scripting ≤ 1.0.5 CVE-2025-58882 Patchstack
6.5 Medium Slider Revolution Plugin Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' ≤ 6.7.36 CVE-2025-9217 Wordfence
5.8 Medium B Slider Plugin b-slider Broken Access Control No login needed ≤ 1.1.30 Fixed in 2.0.0 CVE-2025-54734 Patchstack
6.5 Medium bxSlider integration Plugin bxslider-integration Cross-Site Scripting ≤ 1.7.2 CVE-2025-48347 Patchstack
5.9 Medium WP Thumbtack Review Slider Plugin wp-thumbtack-review-slider Cross-Site Scripting ≤ 2.6 Fixed in 2.7 CVE-2025-58216 Patchstack
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Server-Side Request Forgery Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 2.0.0 CVE-2025-8680 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 2.0.0 CVE-2025-8676 Wordfence
6.4 Medium Simple Responsive Slider Plugin addi-simple-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-8690 Wordfence
6.4 Medium BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites Plugin blockspare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets ≤ 3.2.13.1 CVE-2025-4684 Wordfence
4.9 Medium Smart Slider 3 Plugin smart-slider-3 SQL Injection Authenticated (Administrator+) SQL Injection via `sliderid` Parameter ≤ 3.5.1.28 CVE-2025-6348 Wordfence
6.4 Medium Wonder Slider Lite & Wonder Slider Plugin wonderplugin-slider-lite Cross-Site Scripting Authenticated (Contributor+) Dom-based Stored Cross-Site Scripting ≤ 14.4 CVE-2025-7501 Wordfence
6.4 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link ≤ 7.4.2 CVE-2025-8015 Wordfence
6.1 Medium Latest Post Accordian Slider Plugin latest-post-accordian-slider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-7687 Wordfence
6.4 Medium Vertical scroll image slideshow gallery Plugin vertical-scroll-image-slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 11.1 CVE-2025-5752 Wordfence
4.3 Medium Block Editor Gallery Slider Plugin block-editor-gallery-slider Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update ≤ 1.1.1 CVE-2025-6726 Wordfence
6.4 Medium Simple Featured Image Plugin simple-featured-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter ≤ 1.3.1 CVE-2025-7059 Wordfence
6.5 Medium Card flip image slideshow Plugin card-flip-image-slideshow Cross-Site Scripting ≤ 1.5 CVE-2025-30983 Patchstack
6.5 Medium Posts Slider Shortcode Plugin posts-slider-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-30943 Patchstack
6.5 Medium HT Slider For Elementor Plugin ht-slider-for-elementor Cross-Site Scripting ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-53199 Patchstack
4.3 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Broken Access Control Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function ≤ 1.6.0 CVE-2025-3863 Wordfence
6.4 Medium Master Slider Plugin master-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes ≤ 3.10.8 CVE-2025-5291 Wordfence
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
4.3 Medium GPP Slideshow Plugin gpp-slideshow Broken Access Control ≤ 1.3.5 CVE-2025-28996 Patchstack
5.9 Medium WP Featured Content Slider Plugin wp-featured-content-slider Cross-Site Scripting ≤ 2.6 CVE-2025-30634 Patchstack
4.8 Medium Post Slider and Carousel with Widget Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.10 Fixed in 3.2.10 CVE-2025-4567 WPScan
6.5 Medium Woo Slider Pro - Drag Drop Slider Builder For WooCommerce Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Drag Drop Slider Builder For WooCommerce <= 1.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 1.12 CVE-2025-4597 Wordfence
6.5 Medium Woo Slider Pro Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.12 CVE-2025-48334 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only