WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 251 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium AI Responsive Gallery Album Plugin ai-responsive-gallery-album Broken Access Control ≤ 1.4 CVE-2025-23785 Patchstack
6.4 Medium WP Responsive Tabs Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.9 CVE-2024-13387 Wordfence
6.5 Medium Responsive jQuery Slider Plugin responsive-jquery-slider Cross-Site Scripting ≤ 1.1.1 CVE-2025-22798 Patchstack
6.1 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Cross-Site Scripting Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2024-12403 Wordfence
6.5 Medium Responsive Flickr Slideshow Plugin mobile-friendly-flickr-slideshow Cross-Site Scripting ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-22807 Patchstack
6.4 Medium Responsive FlipBook Plugin Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.5.0 CVE-2024-11929 Wordfence
6.4 Medium Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites Plugin common-ninja Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11382 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2023-45631 Patchstack
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
6.5 Medium Responsive Google Maps | by imbaa Plugin responsive-google-maps Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.5 Fixed in 1.2.7 CVE-2024-56011 Patchstack
9.8 Critical Flash News / Post (Responsive) Plugin flashnews-fading-effect-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.1 CVE-2024-56012 Patchstack
6.1 Medium WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More Plugin wp-ad-guru Cross-Site Scripting Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2024-12411 Wordfence
6.4 Medium Companion Portfolio – Responsive Portfolio Plugin companion-portfolio Cross-Site Scripting Responsive Portfolio Plugin <= 2.4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0.1 CVE-2024-11867 Wordfence
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
6.5 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.8 CVE-2019-25221 Wordfence
8.8 High Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Local File Inclusion Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion ≤ 3.3.3 CVE-2024-11429 Wordfence
6.4 Medium Responsive Videos Plugin responsive-youtube-videos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-11747 Wordfence
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
6.5 Medium WP Responsive Video Plugin my-wp-responsive-video Cross-Site Scripting ≤ 1.0 CVE-2024-51940 Patchstack
9.8 Critical WDES Responsive Mobile Menu Plugin wdes-responsive-mobile-menu PHP Object Injection No login needed ≤ 5.3.18 CVE-2024-52414 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
6.5 Medium ML Responsive Audio player with playlist Shortcode Plugin mlr-audio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2 CVE-2024-51573 Patchstack
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High SrcSet Responsive Images Plugin truenorth-srcset Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-51702 Patchstack
7.1 High Responsive Data Table Plugin responsive-data-table Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51710 Patchstack
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
6.5 Medium wpPricing Builder Plugin wppricing-builder-lite-responsive-pricing-table-builder Cross-Site Scripting ≤ 1.5.0 CVE-2024-49225 Patchstack
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
5.9 Medium Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2024-49282 Patchstack
6.5 Medium Logo Carousel – Clients logo carousel for WP Plugin responsive-client-logo-carousel-slider Cross-Site Scripting Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) ≤ 1.2 Fixed in 1.3.0 CVE-2024-47631 Patchstack
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence
6.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via File Upload ≤ 2.4.7 CVE-2024-6870 Wordfence
6.4 Medium Responsive Video Plugin responsive-video Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-7629 Wordfence
6.5 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks plugin <= 1.8.8 - Cross Site Scripting (XSS) ≤ 1.8.8 Fixed in 1.8.9 CVE-2024-43335 Patchstack
5.3 Medium Coming Soon Plugin responsive-coming-soon-page Information Disclosure Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure No login needed ≤ 1.6.3 CVE-2024-38756 Patchstack
5.3 Medium SmartMag Theme smartmag-responsive-retina-wordpress-magazine Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 10.1.0 Fixed in 10.1.0 CVE-2024-37930 Patchstack
8.8 High Slider by 10Web – Responsive Image Slider Plugin slider-wd SQL Injection Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.2.57 CVE-2024-7150 Wordfence
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
5.9 Medium Responsive Tabs Plugin responsive-tabs Cross-Site Scripting Contributor+ Stored XSS ≤ 4.0.8 CVE-2024-4096 WPScan
6.5 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion No login needed ≤ 3.9.10 CVE-2024-6490 WPScan
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Responsive Mobile Theme responsive-mobile Cross-Site Scripting ≤ 1.15.1 CVE-2024-37949 Patchstack
7.1 High Simple Responsive Slider Plugin simple-responsive-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.2.5 CVE-2024-37954 Patchstack
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only