WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 151–200 of 383 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
4.3 Medium Master Slider Plugin master-slider Broken Access Control ≤ 3.11.0 CVE-2025-39412 Patchstack
6.5 Medium WP Vegas Plugin vegas-fullscreen-background-slider Cross-Site Scripting ≤ 2.2 CVE-2025-43841 Patchstack
4.3 Medium GS Logo Slider Plugin Cross-Site Request Forgery Settings Update via Cross-Site Request Forgery No login needed < 3.7.1 Fixed in 3.7.1 CVE-2024-9233 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.24 Fixed in 3.2.24 CVE-2024-13384 WPScan
4.8 Medium Ditty – Responsive News Tickers, Sliders, and Lists Plugin ditty-news-ticker Cross-Site Scripting Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS < 3.1.52 Fixed in 3.1.52 CVE-2024-13357 WPScan
4.8 Medium Full Screen (Page) Background Image Slideshow Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.1 CVE-2024-11221 WPScan
4.8 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Scripting Admin+ Stored XSS < 15.6 Fixed in 15.6 CVE-2024-11109 WPScan
4.8 Medium Social Slider Feed Plugin instagram-slider-widget Cross-Site Scripting Admin+ Stored XSS via Widgets < 2.2.9 Fixed in 2.2.9 CVE-2024-10149 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10144 WPScan
5.3 Medium GS Testimonial Slider Plugin gs-testimonial Content Injection No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-47481 Patchstack
4.3 Medium GS Testimonial Slider Plugin gs-testimonial Broken Access Control ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-47467 Patchstack
6.1 Medium Advanced Reorder Image Text Slider Plugin abundatrade-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-4188 Wordfence
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
6.5 Medium Logo Carousel Slider Plugin logo-carousel-slider Cross-Site Scripting ≤ 2.1.3 CVE-2025-39525 Patchstack
6.4 Medium Logo Carousel Gutenberg Block Plugin awesome-logo-carousel-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter ≤ 2.1.6 CVE-2025-2083 Wordfence
4.9 Medium Team Circle Image Slider With Lightbox Plugin circle-image-slider-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2019-25223 Wordfence
6.5 Medium Gosign – Posts Slider Block Plugin gosign-posts-slider-block Cross-Site Scripting Posts Slider Block plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-31891 Patchstack
4.3 Medium GB Gallery Slideshow Plugin gb-gallery-slideshow Broken Access Control ≤ 1.3 CVE-2025-31732 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
5.9 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Scripting ≤ 1.0.1 CVE-2025-31587 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Broken Access Control ≤ 1.0.1 CVE-2025-31584 Patchstack
4.3 Medium Slider Path for Elementor Plugin slider-path Broken Access Control ≤ 3.0.0 CVE-2025-31529 Patchstack
6.5 Medium Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting ≤ 3.1.5 CVE-2025-26738 Patchstack
6.5 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Scripting ≤ 0.5.8.2 Fixed in 0.5.8.4 CVE-2025-30860 Patchstack
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Contributor+ Stored XSS No login needed < 1.2.62 Fixed in 1.2.62 CVE-2024-10566 WPScan
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Admin+ Stored XSS via Widget No login needed < 1.2.62 Fixed in 1.2.62 CVE-2024-10565 WPScan
5.9 Medium WP Parallax Content Slider Plugin wp-parallax-content-slider Cross-Site Scripting ≤ 0.9.8 CVE-2025-30599 Patchstack
4.9 Medium Thumbnail carousel slider Plugin wp-responsive-thumbnail-slider SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2019-25222 Wordfence
5.9 Medium Skitter Slideshow Plugin wp-skitter-slideshow Cross-Site Scripting ≤ 2.5.2 CVE-2025-28906 Patchstack
6.5 Medium Bee Layer Slider Plugin bee-layer-slider Cross-Site Scripting ≤ 1.1 CVE-2025-28879 Patchstack
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode ≤ 3.10.7 CVE-2024-11731 Wordfence
6.5 Medium Hero Slider - WordPress Slider Plugin SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.3.5 CVE-2024-13809 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.10.6 CVE-2024-13757 Wordfence
6.3 Medium radSLIDE Plugin radslide Broken Access Control Broken Access Control to Stored Cross-Site Scripting ≤ 2.1 CVE-2025-23440 Patchstack
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.6.0 Fixed in 4.6.0 CVE-2024-12308 WPScan
6.4 Medium Responsive Flickr Slideshow Plugin mobile-friendly-flickr-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13660 Wordfence
4.7 Medium WP Touch Slider Plugin Cross-Site Scripting Reflected XSS ≤ 2.2 CVE-2024-13627 WPScan
4.3 Medium Slide Banners Plugin slide-banners Broken Access Control ≤ 1.3 CVE-2025-25120 Patchstack
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
6.1 Medium SlideDeck 1 Lite Content Slider Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.4.8 CVE-2024-13224 WPScan
6.4 Medium Gosign – Posts Slider Block Plugin gosign-posts-slider-block Cross-Site Scripting Posts Slider Block <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-13399 Wordfence
6.4 Medium WE – Testimonial Slider Plugin we-testimonial-slider Cross-Site Scripting Testimonial Slider <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5 CVE-2024-13460 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
4.3 Medium Super Block Slider Plugin super-block-slider Broken Access Control ≤ 2.7.9 Fixed in 2.8 CVE-2025-24682 Patchstack
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.16.5 CVE-2024-12043 Wordfence
5.4 Medium Slides & Presentations Plugin slide Content Injection ≤ 0.0.39 CVE-2025-23919 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only