WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 201–250 of 343 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | ST Gallery WP | Broken Access Control Settings Change |
≤ 1.0.8 |
CVE-2025-22543 |
Patchstack | |
| 6.4 Medium | WP Youtube Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 1.9 |
CVE-2024-12590 |
Wordfence | |
| 4.3 Medium | Photo Gallery Slideshow & Masonry Tiled Gallery | Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery |
≤ 1.0.15 |
CVE-2024-12237 |
Wordfence | |
| 4.3 Medium | Gallery Images Ape | Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control |
≤ 2.2.8 |
CVE-2022-41995 |
Patchstack | |
| 5.9 Medium | Contest Gallery | Cross-Site Scripting |
≤ 24.0.3 Fixed in 24.0.4 |
CVE-2024-56237 |
Patchstack | |
| 4.3 Medium | Responsive Image Gallery, Gallery Album | Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control |
≤ 2.0.3 |
CVE-2023-45631 |
Patchstack | |
| 6.1 Medium | Exhibit to WP Gallery | Cross-Site Scripting Reflected XSS No login needed |
≤ 0.0.2 |
CVE-2024-12096 |
WPScan | |
| 6.4 Medium | Portfolio – Filterable Masonry Portfolio Gallery for Professionals | Cross-Site Scripting Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.2 |
CVE-2024-11900 |
Wordfence | |
| 4.3 Medium | Automatic YouTube Gallery | Broken Access Control |
≤ 2.3.3 Fixed in 2.3.5 |
CVE-2023-41866 |
Patchstack | |
| 4.3 Medium | Justified Gallery | Broken Access Control |
≤ 1.7.3 Fixed in 1.8.0 |
CVE-2023-40213 |
Patchstack | |
| 4.3 Medium | Photo Gallery by 10Web | Broken Access Control |
≤ 1.8.15 Fixed in 1.8.16 |
CVE-2023-33995 |
Patchstack | |
| 5.4 Medium | Robo Gallery | Broken Access Control Auth. Broken Access Control |
≤ 3.2.9 Fixed in 3.2.11 |
CVE-2022-45841 |
Patchstack | |
| 6.1 Medium | Video & Photo Gallery for Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.1 |
CVE-2024-12162 |
Wordfence | |
| 5.3 Medium | Album and Image Gallery plus Lightbox | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2023-25060 |
Patchstack | |
| 6.1 Medium | Folder Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting No login needed |
≤ 1.7.4 |
CVE-2024-11823 |
Wordfence | |
| 4.4 Medium | Video Gallery | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 2.4.1 |
CVE-2024-9769 |
Wordfence | |
| 6.4 Medium | WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout | Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.8.8 |
CVE-2024-11453 |
Wordfence | |
| 6.5 Medium | Elementor Image Gallery | Cross-Site Scripting |
≤ 1.0.5 Fixed in 1.0.6 |
CVE-2024-53744 |
Patchstack | |
| 5.9 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-53788 |
Patchstack | |
| 4.8 Medium | Photo Gallery by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.8.31 Fixed in 1.8.31 |
CVE-2024-10704 |
WPScan | |
| 6.4 Medium | BNE Gallery Extended | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode |
≤ 1.2.1 |
CVE-2024-11119 |
Wordfence | |
| 6.3 Medium | InPost Gallery | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template |
≤ 2.1.4.2 |
CVE-2024-11002 |
Wordfence | |
| 4.8 Medium | NextGEN Gallery | Cross-Site Scripting Admin+ Stored XSS |
< 3.59.5 Fixed in 3.59.5 |
CVE-2024-6393 |
WPScan | |
| 5.5 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 3.2.4.2 |
CVE-2024-10034 |
Wordfence | |
| 6.5 Medium | drop in image slideshow gallery | Cross-Site Scripting |
≤ 12.0 |
CVE-2024-51914 |
Patchstack | |
| 6.1 Medium | Gallery Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.58 |
CVE-2024-10875 |
Wordfence | |
| 5.3 Medium | Video Gallery for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed |
≤ 1.31 |
CVE-2024-10535 |
Wordfence | |
| 4.4 Medium | Photo Gallery by 10Web | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.8.30 |
CVE-2024-9878 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget |
≤ 5.10.1 |
CVE-2024-10310 |
Wordfence | |
| 4.3 Medium | Envira Photo Gallery | Cross-Site Request Forgery CSRF leading to notice dismissal |
≤ 1.8.7.3 Fixed in 1.8.8 |
CVE-2024-37095 |
Patchstack | |
| 6.5 Medium | WP Social Feed Gallery | Broken Access Control No login needed |
≤ 4.3.9 Fixed in 4.4.0 |
CVE-2024-39640 |
Patchstack | |
| 4.3 Medium | Envira Photo Gallery | Broken Access Control |
≤ 1.8.14 Fixed in 1.8.15 |
CVE-2024-43925 |
Patchstack | |
| 5.9 Medium | Robo Gallery | Cross-Site Scripting |
≤ 3.2.21 Fixed in 3.2.22 |
CVE-2024-49696 |
Patchstack | |
| 5.3 Medium | Responsive Lightbox | Broken Access Control No login needed |
≤ 2.4.7 Fixed in 2.4.8 |
CVE-2024-43924 |
Patchstack | |
| 4.3 Medium | Photo Gallery Builder | Broken Access Control Broken Access Control to Notice Dismissal |
≤ 3.0 |
CVE-2024-49325 |
Patchstack | |
| 4.9 Medium | Photo Gallery Slideshow & Masonry Tiled Gallery | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.3 |
CVE-2019-25218 |
Wordfence | |
| 6.5 Medium | Lightbox slider – Responsive Lightbox Gallery | Cross-Site Scripting |
≤ 1.10.6 |
CVE-2024-49280 |
Patchstack | |
| 5.9 Medium | Responsive Lightbox | Cross-Site Scripting |
≤ 2.4.8 Fixed in 2.4.9 |
CVE-2024-49282 |
Patchstack | |
| 6.5 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-49302 |
Patchstack | |
| 6.5 Medium | WordPress Gallery Plugin – Limb Image Gallery | Path Traversal Arbitrary File Download |
≤ 1.5.7 |
CVE-2024-49258 |
Patchstack | |
| 4.4 Medium | ImagePress - Image Gallery | Cross-Site Scripting Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.2.2 |
CVE-2024-9776 |
Wordfence | |
| 4.3 Medium | ImagePress - Image Gallery | Broken Access Control Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update |
≤ 1.2.2 |
CVE-2024-9824 |
Wordfence | |
| 4.3 Medium | ImagePress – Image Gallery | Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.2.2 |
CVE-2024-9778 |
Wordfence | |
| 4.8 Medium | Photo Gallery by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.8.28 Fixed in 1.8.28 |
CVE-2024-5968 |
WPScan | |
| 4.3 Medium | Photo Gallery, Images, Slider in Rbs Image Gallery | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure |
≤ 3.2.21 |
CVE-2024-8431 |
Wordfence | |
| 5.9 Medium | Photo Gallery by 10Web | Cross-Site Scripting |
≤ 1.8.27 Fixed in 1.8.28 |
CVE-2024-44043 |
Patchstack | |
| 5.9 Medium | Slideshow Gallery | Cross-Site Scripting |
≤ 1.8.3 Fixed in 1.8.4 |
CVE-2024-47376 |
Patchstack | |
| 5.9 Medium | Gallery Lightbox | Cross-Site Scripting |
≤ 1.0.0.39 Fixed in 1.0.0.41 |
CVE-2024-47623 |
Patchstack | |
| 5.3 Medium | Sight – Professional Image Gallery and Portfolio | Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed |
≤ 1.1.2 |
CVE-2024-9025 |
Wordfence | |
| 4.3 Medium | WP Easy Gallery – WordPress Gallery | Broken Access Control WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation |
≤ 4.8.5 |
CVE-2024-8437 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.