WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 201–250 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting ≤ 6.3.8 Fixed in 6.3.9 CVE-2025-57947 Patchstack
6.5 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.41 Fixed in 1.0.0.43 CVE-2025-57966 Patchstack
5.9 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Scripting ≤ 1.5.5 CVE-2025-57974 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure No login needed ≤ 1.16.16 Fixed in 1.16.17 CVE-2025-58226 Patchstack
6.4 Medium Easy Social Feed – Social Photos Gallery – Post Feed – Like Box Plugin easy-facebook-likebox Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.6.7 CVE-2025-6067 Wordfence
7.5 High InPost Gallery Plugin inpost-gallery Local File Inclusion ≤ 2.1.4.5 CVE-2025-57889 Patchstack
8.5 High New Simple Gallery Plugin new-simple-gallery SQL Injection ≤ 8.0 CVE-2025-58881 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-58610 Patchstack
7.1 High NextGEN Gallery Search Plugin nextgen-gallery-search-galleries Cross-Site Scripting No login needed ≤ 2.12 CVE-2025-53224 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
8.8 High Vertical scroll slideshow gallery v2 Plugin vertical-scroll-slideshow-gallery-v2 SQL Injection ≤ 9.1 CVE-2025-49897 Patchstack
7.5 High Assistant for NextGEN Gallery Plugin assistant-for-nextgen-gallery Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.0.9 CVE-2025-7641 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' ≤ 6.2.2 CVE-2025-8451 Wordfence
4.3 Medium flexo-social-gallery Plugin flexo-social-gallery Cross-Site Request Forgery No login needed ≤ 1.0006 CVE-2025-52769 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.2.0.2 Fixed in 2.2.0.3 CVE-2025-54749 Patchstack
6.5 Medium Global Gallery Plugin global-gallery Broken Access Control No login needed ≤ 9.2.3 Fixed in 9.2.4 CVE-2025-52721 Patchstack
6.1 Medium Image Gallery Plugin bee-quick-gallery Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-8400 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.1.0 CVE-2025-7725 Wordfence
6.4 Medium Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery Plugin Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2025-7644 Wordfence
6.4 Medium Vertical scroll image slideshow gallery Plugin vertical-scroll-image-slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 11.1 CVE-2025-5752 Wordfence
4.3 Medium Block Editor Gallery Slider Plugin block-editor-gallery-slider Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update ≤ 1.1.1 CVE-2025-6726 Wordfence
8.8 High Visual Art | Gallery Plugin visual-arts PHP Object Injection ≤ 2.4 CVE-2025-31422 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 26.0.6 Fixed in 26.0.7 CVE-2025-48291 Patchstack
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 CVE-2025-6068 Wordfence
6.4 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 26.0.8 CVE-2025-6716 Wordfence
10.0 Critical FW Gallery Plugin fw-gallery Arbitrary File Upload No login needed ≤ 8.0.0 CVE-2025-49414 Patchstack
8.5 High Pixelating image slideshow gallery Plugin pixelating-image-slideshow-gallery SQL Injection ≤ 8.0 CVE-2025-30979 Patchstack
8.5 High iFrame Images Gallery Plugin wp-iframe-images-gallery SQL Injection ≤ 9.0 CVE-2025-30969 Patchstack
8.5 High Gallery Widget Plugin gallery-widget SQL Injection ≤ 1.2.1 CVE-2025-28969 Patchstack
6.5 Medium Video Gallery Block Plugin video-gallery-block Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-27326 Patchstack
6.4 Medium Portfolio for Elementor & Image Gallery | PowerFolio Plugin portfolio-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.2.0 CVE-2025-7046 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library ≤ 2.6.7, ≤ 3.5, ≤ 3.59.11 CVE-2025-2537 Wordfence
7.5 High Gmedia Photo Gallery Plugin grand-media Local File Inclusion ≤ 1.23.0 Fixed in 1.24.0 CVE-2025-53257 Patchstack
8.1 High FW Gallery Plugin fw-gallery Local File Inclusion No login needed ≤ 8.0.0 CVE-2025-49416 Patchstack
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Contributor+ Stored XSS < 2.5.2 Fixed in 2.5.2 CVE-2025-5093 WPScan
7.5 High Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery Plugin aeroscroll-gallery Path Traversal Infinite Scroll Image Gallery & Post Grid with Photo Gallery plugin <= 1.0.13 - Directory Traversal No login needed ≤ 1.0.13 CVE-2025-49451 Patchstack
8.6 High FW Gallery Plugin fw-gallery Arbitrary File Deletion No login needed ≤ 8.0.0 CVE-2025-49415 Patchstack
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter ≤ 3.98.0 CVE-2025-5337 Wordfence
7.5 High Apptha Slider Gallery Plugin apptha-slider-gallery Path Traversal Arbitrary File Read No login needed ≤ 2.5 CVE-2025-31050 Patchstack
6.5 Medium YouTube Simple Gallery Plugin youtube-simple-gallery Cross-Site Scripting ≤ 2.2.0 CVE-2025-29011 Patchstack
6.4 Medium Paged Gallery Plugin paged-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.7 CVE-2025-5686 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin nextgen-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library ≤ 2.14.4, ≤ 3.59.4 CVE-2024-5878 Wordfence
3.5 Low Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS < 2.3.15 Fixed in 2.3.15 CVE-2024-4091 WPScan
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Editor+ Stored XSS < 2.6.9 Fixed in 2.6.9 CVE-2024-4002 WPScan
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.29 Fixed in 1.8.29 CVE-2024-8670 WPScan
6.1 Medium Smooth Gallery Replacement Plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-8032 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.24 Fixed in 3.2.24 CVE-2024-13384 WPScan
4.8 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10144 WPScan
6.8 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Contributor+ Stored XSS < 2.5.1 Fixed in 2.5.1 CVE-2025-3742 WPScan
6.4 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 26.0.6 CVE-2025-3862 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only