WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 151–200 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Famous - Responsive Image And Video Grid Gallery Plugin famous_grid_image_and_video_gallery Cross-Site Scripting Responsive Image And Video Grid Gallery WordPress Plugin plugin <= 1.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-27004 Patchstack
9.8 Critical DZS Video Gallery Plugin dzs-videogallery PHP Object Injection No login needed ≤ 12.37 CVE-2025-47552 Patchstack
7.1 High DZS Video Gallery Plugin dzs-videogallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.25 CVE-2025-32300 Patchstack
6.4 Medium My Album Gallery Plugin my-album-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style_css' Shortcode Attribute ≤ 1.0.4 CVE-2025-14453 Wordfence
6.4 Medium STM Gallery 1.9 Plugin stm-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.9 CVE-2025-13848 Wordfence
6.4 Medium My Album Gallery Plugin my-album-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title ≤ 1.0.4 CVE-2025-14796 Wordfence
8.8 High DZS Video Gallery Plugin dzs-videogallery PHP Object Injection ≤ 12.25 CVE-2025-47553 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.26 Fixed in 2.7.7.27 CVE-2025-69084 Patchstack
7.1 High Zielke Design Project Gallery Plugin zielke-design-project-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23705 Patchstack
4.3 Medium Accordion Slider Gallery Plugin accordion-slider-gallery Broken Access Control ≤ 2.7 CVE-2025-62130 Patchstack
4.3 Medium Gmedia Photo Gallery Plugin grand-media Cross-Site Request Forgery No login needed ≤ 1.25.0 CVE-2025-63014 Patchstack
4.3 Medium Post Video Players Plugin video-playlist-and-gallery-plugin Information Disclosure Sensitive Data Exposure ≤ 1.163 CVE-2025-62143 Patchstack
5.4 Medium Portfolio Gallery Plugin gallery-portfolio Broken Access Control ≤ 1.4.8 CVE-2025-62098 Patchstack
5.9 Medium Post Video Players Plugin video-playlist-and-gallery-plugin Cross-Site Scripting ≤ 1.163 CVE-2025-62142 Patchstack
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting ≤ 3.6.8 CVE-2025-13693 Wordfence
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Gallery Management ≤ 3.6.7 CVE-2025-14455 Wordfence
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template' ≤ 3.59.12 CVE-2025-13641 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification ≤ 2.13.3 CVE-2025-14003 Wordfence
4.3 Medium Gallery Blocks with Lightbox Plugin simply-gallery-block Broken Access Control Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification ≤ 3.3.0 CVE-2025-14288 Wordfence
6.5 Medium Image Gallery – Photo Grid & Video Gallery (Modula) Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing ≤ 2.13.3 CVE-2025-13891 Wordfence
4.3 Medium Vimeo SimpleGallery Plugin vimeo-simplegallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification ≤ 0.2 CVE-2025-14170 Wordfence
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting ≤ 3.3.2.1 Fixed in 3.3.2.2 CVE-2025-63052 Patchstack
6.5 Medium JNews Gallery Plugin jnews-gallery Cross-Site Scripting ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67538 Patchstack
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Import ZIP 4.5.4 – 4.5.7 CVE-2025-12966 Wordfence
6.4 Medium Social Feed Gallery Portfolio Plugin social-feed-gallery-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.3 CVE-2025-13896 Wordfence
6.1 Medium dream gallery Plugin dream-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed ≤ 1.0 CVE-2025-13621 Wordfence
8.8 High PostGallery Plugin postgallery Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.12.5 CVE-2025-13543 Wordfence
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence
7.2 High Modula Plugin modula-best-grid-gallery Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion 2.13.1 – 2.13.2 CVE-2025-13645 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
8.1 High WP AUDIO GALLERY Plugin wp-audio-gallery Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' Parameter ≤ 2.0 CVE-2025-13322 Wordfence
6.4 Medium Multiple Plugins and Themes <= (Various Versions) Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library ≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … CVE-2025-5092 Wordfence
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 2.5.3 CVE-2025-12359 Wordfence
6.4 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Caption Attribute ≤ 3.21 CVE-2025-12691 Wordfence
5.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control Missing Authorization No login needed ≤ 28.0.2 CVE-2025-12849 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Arbitrary File Deletion Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move ≤ 2.12.28 CVE-2025-12494 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions ≤ 1.12.0 CVE-2025-12377 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion ≤ 1.11.0 CVE-2025-11448 Wordfence
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
7.1 High Image Gallery block – Create and display photo gallery/photo album. Plugin 3d-image-gallery Authentication Bypass Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication ≤ 1.0.7 Fixed in 2.0.0 CVE-2025-49394 Patchstack
6.5 Medium Video Gallery by Huzzaz Plugin huzzaz-video-gallery Cross-Site Scripting ≤ 10.5 CVE-2025-62910 Patchstack
5.3 Medium Social Feed Gallery Plugin insta-gallery Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 4.9.2 CVE-2025-10637 Wordfence
6.4 Medium WP AD Gallery Plugin wp-ad-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2025-11834 Wordfence
9.8 Critical Flickr Gallery Plugin flickr-gallery PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.5.3 Fixed in 1.5.3 CVE-2017-20207 Wordfence
4.3 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Content Injection Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection No login needed ≤ 27.0.3 CVE-2025-11254 Wordfence
6.3 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-9710 WPScan
6.4 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 27.0.2 CVE-2025-10383 Wordfence
6.5 Medium Woo superb slideshow transition gallery with random effect Plugin woo-superb-slideshow-transition-gallery-with-random-effect SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.1 CVE-2025-9199 Wordfence
5.9 Medium Gallery Custom Links Plugin gallery-custom-links Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-60104 Patchstack
6.5 Medium Fusion Page Builder : Extension – Gallery Plugin fusion-extension-gallery Cross-Site Scripting Gallery Plugin <= 1.7.6 - Cross Site Scripting (XSS) ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-58965 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only