WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 151–200 of 343 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Smooth Gallery Replacement Plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-8032 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.24 Fixed in 3.2.24 CVE-2024-13384 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10144 WPScan
6.8 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Contributor+ Stored XSS < 2.5.1 Fixed in 2.5.1 CVE-2025-3742 WPScan
6.4 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 26.0.6 CVE-2025-3862 Wordfence
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) ≤ 2.7.7.25 Fixed in 2.7.7.26 CVE-2025-47677 Patchstack
6.5 Medium Awesome Gallery Plugin awesome-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-47632 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2025-47521 Patchstack
5.9 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting ≤ 5.2.7 Fixed in 5.2.8 CVE-2025-47449 Patchstack
6.5 Medium Awesome Wp Image Gallery Plugin awesome-wp-image-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-46476 Patchstack
6.4 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id' ≤ 2.4.6 CVE-2025-3458 Wordfence
4.3 Medium InPost Gallery Plugin inpost-gallery Cross-Site Request Forgery No login needed ≤ 2.1.4.3 Fixed in 2.1.4.4 CVE-2025-26903 Patchstack
6.1 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter No login needed ≤ 1.8.34 CVE-2025-2269 Wordfence
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-32176 Patchstack
6.4 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library ≤ 2.10.1 CVE-2024-9416 Wordfence
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
4.3 Medium GB Gallery Slideshow Plugin gb-gallery-slideshow Broken Access Control ≤ 1.3 CVE-2025-31732 Patchstack
6.5 Medium Gallery – Photo Albums Plugin easy-media-gallery Cross-Site Scripting Photo Albums Plugin plugin <= 1.3.170 - Stored Cross Site Scripting (XSS) ≤ 1.3.170 CVE-2025-31586 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.1.22 Fixed in 2.1.22.1 CVE-2025-31412 Patchstack
6.1 Medium Photo Gallery Plugin photo-gallery Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.8.34 Fixed in 1.8.34 CVE-2025-0613 WPScan
6.5 Medium YouTube SimpleGallery Plugin youtube-simplegallery Cross-Site Scripting ≤ 2.0.6 CVE-2025-31453 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
6.5 Medium Gallery for Social Photo Plugin feed-instagram-lite Cross-Site Scripting ≤ 1.0.0.35 Fixed in 1.0.0.37 CVE-2025-26742 Patchstack
6.4 Medium Gallery Styles Plugin gallery-styles Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 CVE-2025-1783 Wordfence
4.3 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates ≤ 2.4.29 CVE-2024-12114 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size ≤ 2.4.29 CVE-2024-12119 Wordfence
6.4 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-1757 Wordfence
5.1 Medium FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed 2.4.29 CVE-2025-22624 Fluid Attacks
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.6.0 CVE-2024-6261 Wordfence
6.4 Medium 3D Photo Gallery Plugin 3d-photo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13751 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.5 Medium Categorized Gallery Plugin categorized-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.0 CVE-2024-13676 Wordfence
5.9 Medium Gallery Plugin gallery Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-26778 Patchstack
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget ≤ 2.1.8 CVE-2024-13644 Wordfence
5.4 Medium Global Gallery - WordPress Responsive Gallery Plugin Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 9.1.5 CVE-2024-13814 Wordfence
6.5 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-25080 Patchstack
6.5 Medium NextGen Cooliris Gallery Plugin nextgen-cooliris-gallery Cross-Site Scripting ≤ 0.7 CVE-2025-25091 Patchstack
6.5 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.2 CVE-2025-24697 Patchstack
6.4 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13400 Wordfence
5.3 Medium picu Plugin picu Broken Access Control Online Photo Proofing Gallery plugin <= 2.4.0 - Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24590 Patchstack
6.4 Medium Masy Gallery Plugin masy-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13586 Wordfence
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
6.4 Medium Simple Gallery with Filter Plugin simple-gallery-with-filter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-13583 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.19 CVE-2024-13584 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode ≤ 1.5.22 CVE-2024-12696 Wordfence
6.5 Medium Gallery: Hybrid – Advanced Visual Gallery Plugin hybrid-gallery Cross-Site Scripting Advanced Visual Gallery plugin <= 1.4.0.2 - Cross Site Scripting (XSS) ≤ 1.4.0.2 CVE-2025-23951 Patchstack
4.3 Medium AI Responsive Gallery Album Plugin ai-responsive-gallery-album Broken Access Control ≤ 1.4 CVE-2025-23785 Patchstack
6.5 Medium Gallery and Lightbox Plugin gallery-and-lightbox Cross-Site Scripting ≤ 1.0.14 CVE-2025-22797 Patchstack
6.1 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Cross-Site Scripting Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2024-12403 Wordfence
6.5 Medium Justified Image Gallery Plugin justified-image-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-22518 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only