WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 201–250 of 343 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium ST Gallery WP Plugin st-gallery-wp Broken Access Control Settings Change ≤ 1.0.8 CVE-2025-22543 Patchstack
6.4 Medium WP Youtube Gallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9 CVE-2024-12590 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
5.9 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-56237 Patchstack
4.3 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2023-45631 Patchstack
6.1 Medium Exhibit to WP Gallery Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.0.2 CVE-2024-12096 WPScan
6.4 Medium Portfolio – Filterable Masonry Portfolio Gallery for Professionals Plugin portfolio-pro Cross-Site Scripting Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-11900 Wordfence
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Justified Gallery Plugin justified-gallery Broken Access Control ≤ 1.7.3 Fixed in 1.8.0 CVE-2023-40213 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.15 Fixed in 1.8.16 CVE-2023-33995 Patchstack
5.4 Medium Robo Gallery Plugin robo-gallery Broken Access Control Auth. Broken Access Control ≤ 3.2.9 Fixed in 3.2.11 CVE-2022-45841 Patchstack
6.1 Medium Video & Photo Gallery for Ultimate Member Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2024-12162 Wordfence
5.3 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2023-25060 Patchstack
6.1 Medium Folder Gallery Plugin folder-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2024-11823 Wordfence
4.4 Medium Video Gallery Plugin video-wc-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2024-9769 Wordfence
6.4 Medium WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout Plugin gs-pinterest-portfolio Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.8 CVE-2024-11453 Wordfence
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.31 Fixed in 1.8.31 CVE-2024-10704 WPScan
6.4 Medium BNE Gallery Extended Plugin bne-gallery-extended Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode ≤ 1.2.1 CVE-2024-11119 Wordfence
6.3 Medium InPost Gallery Plugin inpost-gallery Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template ≤ 2.1.4.2 CVE-2024-11002 Wordfence
4.8 Medium NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.5 Fixed in 3.59.5 CVE-2024-6393 WPScan
5.5 Medium Mixed Media Gallery Blocks Plugin Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 3.2.4.2 CVE-2024-10034 Wordfence
6.5 Medium drop in image slideshow gallery Plugin drop-in-image-slideshow-gallery Cross-Site Scripting ≤ 12.0 CVE-2024-51914 Patchstack
6.1 Medium Gallery Manager Plugin fancy-gallery Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.58 CVE-2024-10875 Wordfence
5.3 Medium Video Gallery for WooCommerce Plugin video-wc-gallery Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed ≤ 1.31 CVE-2024-10535 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.8.30 CVE-2024-9878 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
6.5 Medium WP Social Feed Gallery Plugin insta-gallery Broken Access Control No login needed ≤ 4.3.9 Fixed in 4.4.0 CVE-2024-39640 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control ≤ 1.8.14 Fixed in 1.8.15 CVE-2024-43925 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 3.2.21 Fixed in 3.2.22 CVE-2024-49696 Patchstack
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
5.9 Medium Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2024-49282 Patchstack
6.5 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-49302 Patchstack
6.5 Medium WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Path Traversal Arbitrary File Download ≤ 1.5.7 CVE-2024-49258 Patchstack
4.4 Medium ImagePress - Image Gallery Plugin image-gallery Cross-Site Scripting Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2.2 CVE-2024-9776 Wordfence
4.3 Medium ImagePress - Image Gallery Plugin image-gallery Broken Access Control Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update ≤ 1.2.2 CVE-2024-9824 Wordfence
4.3 Medium ImagePress – Image Gallery Plugin image-gallery Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.2.2 CVE-2024-9778 Wordfence
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.28 Fixed in 1.8.28 CVE-2024-5968 WPScan
4.3 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure ≤ 3.2.21 CVE-2024-8431 Wordfence
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.27 Fixed in 1.8.28 CVE-2024-44043 Patchstack
5.9 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Scripting ≤ 1.8.3 Fixed in 1.8.4 CVE-2024-47376 Patchstack
5.9 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.39 Fixed in 1.0.0.41 CVE-2024-47623 Patchstack
5.3 Medium Sight – Professional Image Gallery and Portfolio Plugin sight Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed ≤ 1.1.2 CVE-2024-9025 Wordfence
4.3 Medium WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery Broken Access Control WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation ≤ 4.8.5 CVE-2024-8437 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only