WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 201–250 of 562 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Image Slider Widgets |
≤ 3.2.13.1 |
CVE-2025-4684 |
Wordfence | |
| 4.9 Medium | Smart Slider 3 | SQL Injection Authenticated (Administrator+) SQL Injection via `sliderid` Parameter |
≤ 3.5.1.28 |
CVE-2025-6348 |
Wordfence | |
| 6.4 Medium | Wonder Slider Lite & Wonder Slider | Cross-Site Scripting Authenticated (Contributor+) Dom-based Stored Cross-Site Scripting |
≤ 14.4 |
CVE-2025-7501 |
Wordfence | |
| 8.8 High | Responsive Thumbnail Slider | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
< 1.0.1 Fixed in 1.0.1 |
CVE-2015-10144 |
Wordfence | |
| 6.4 Medium | Shortcodes Ultimate | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link |
≤ 7.4.2 |
CVE-2025-8015 |
Wordfence | |
| 6.1 Medium | Latest Post Accordian Slider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.3 |
CVE-2025-7687 |
Wordfence | |
| 6.4 Medium | Vertical scroll image slideshow gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 11.1 |
CVE-2025-5752 |
Wordfence | |
| 4.3 Medium | Block Editor Gallery Slider | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update |
≤ 1.1.1 |
CVE-2025-6726 |
Wordfence | |
| 6.4 Medium | Simple Featured Image | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter |
≤ 1.3.1 |
CVE-2025-7059 |
Wordfence | |
| 6.5 Medium | Card flip image slideshow | Cross-Site Scripting |
≤ 1.5 |
CVE-2025-30983 |
Patchstack | |
| 8.5 High | Pixelating image slideshow gallery | SQL Injection |
≤ 8.0 |
CVE-2025-30979 |
Patchstack | |
| 6.5 Medium | Posts Slider Shortcode | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-30943 |
Patchstack | |
| 7.1 High | Image Slider With Description | Cross-Site Request Forgery No login needed |
≤ 9.2 |
CVE-2025-53308 |
Patchstack | |
| 7.5 High | WPB Category Slider for WooCommerce | Local File Inclusion |
≤ 1.71 |
CVE-2025-53281 |
Patchstack | |
| 6.5 Medium | HT Slider For Elementor | Cross-Site Scripting |
≤ 1.6.5 Fixed in 1.6.6 |
CVE-2025-53199 |
Patchstack | |
| 7.1 High | Off-Canvas Sidebars & Menus (Slidebars) | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.5.8.4 Fixed in 0.5.8.5 |
CVE-2025-49290 |
Patchstack | |
| 4.3 Medium | Post Carousel Slider for Elementor | Broken Access Control Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function |
≤ 1.6.0 |
CVE-2025-3863 |
Wordfence | |
| 6.4 Medium | Master Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via masterslider_pb and ms_slide Shortcodes |
≤ 3.10.8 |
CVE-2025-5291 |
Wordfence | |
| 6.4 Medium | Slider, Gallery, and Carousel by MetaSlider | Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via aria-label Parameter |
≤ 3.98.0 |
CVE-2025-5337 |
Wordfence | |
| 7.5 High | Apptha Slider Gallery | Path Traversal Arbitrary File Read No login needed |
≤ 2.5 |
CVE-2025-31050 |
Patchstack | |
| 7.1 High | Recent Posts Slider Responsive | Cross-Site Request Forgery No login needed |
≤ 1.0.1 |
CVE-2025-28966 |
Patchstack | |
| 4.3 Medium | GPP Slideshow | Broken Access Control |
≤ 1.3.5 |
CVE-2025-28996 |
Patchstack | |
| 5.9 Medium | WP Featured Content Slider | Cross-Site Scripting |
≤ 2.6 |
CVE-2025-30634 |
Patchstack | |
| 4.8 Medium | Post Slider and Carousel with Widget | Cross-Site Scripting Admin+ Stored XSS |
< 3.2.10 Fixed in 3.2.10 |
CVE-2025-4567 |
WPScan | |
| 6.5 Medium | Woo Slider Pro - Drag Drop Slider Builder For WooCommerce | Broken Access Control Drag Drop Slider Builder For WooCommerce <= 1.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 1.12 |
CVE-2025-4597 |
Wordfence | |
| 6.5 Medium | Woo Slider Pro | Broken Access Control Arbitrary Content Deletion |
≤ 1.12 |
CVE-2025-48334 |
Patchstack | |
| 6.4 Medium | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets |
≤ 5.4.0 |
CVE-2025-4682 |
Wordfence | |
| 7.1 High | Theme Blvd Sliders | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.5 |
CVE-2025-46456 |
Patchstack | |
| 4.3 Medium | Master Slider | Broken Access Control |
≤ 3.11.0 |
CVE-2025-39412 |
Patchstack | |
| 6.5 Medium | WP Vegas | Cross-Site Scripting |
≤ 2.2 |
CVE-2025-43841 |
Patchstack | |
| 7.5 High | Product Category Slider for WooCommerce | Local File Inclusion |
≤ 4.3.4 Fixed in 4.3.5 |
CVE-2025-39364 |
Patchstack | |
| 8.5 High | UberSlider | SQL Injection |
≤ 2.6 Fixed in 2.6 |
CVE-2025-31641 |
Patchstack | |
| 8.5 High | Magic Responsive Slider and Carousel | SQL Injection |
≤ 1.6 Fixed in 1.6 |
CVE-2025-31640 |
Patchstack | |
| 3.5 Low | Carousel, Slider, Gallery by WP Carousel | Cross-Site Scripting Editor+ Stored XSS |
< 2.6.9 Fixed in 2.6.9 |
CVE-2024-4002 |
WPScan | |
| 4.3 Medium | GS Logo Slider | Cross-Site Request Forgery Settings Update via Cross-Site Request Forgery No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2024-9233 |
WPScan | |
| 4.8 Medium | Photo Gallery, Images, Slider in Rbs Image Gallery | Cross-Site Scripting Admin+ Stored XSS |
< 3.2.24 Fixed in 3.2.24 |
CVE-2024-13384 |
WPScan | |
| 4.8 Medium | Ditty – Responsive News Tickers, Sliders, and Lists | Cross-Site Scripting Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS |
< 3.1.52 Fixed in 3.1.52 |
CVE-2024-13357 |
WPScan | |
| 4.8 Medium | Full Screen (Page) Background Image Slideshow | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.1 |
CVE-2024-11221 |
WPScan | |
| 4.8 Medium | WP Google Review Slider | Cross-Site Scripting Admin+ Stored XSS |
< 15.6 Fixed in 15.6 |
CVE-2024-11109 |
WPScan | |
| 4.8 Medium | Social Slider Feed | Cross-Site Scripting Admin+ Stored XSS via Widgets |
< 2.2.9 Fixed in 2.2.9 |
CVE-2024-10149 |
WPScan | |
| 4.8 Medium | Photo Gallery, Images, Slider in Rbs Image Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 3.2.22 Fixed in 3.2.22 |
CVE-2024-10144 |
WPScan | |
| 5.3 Medium | GS Testimonial Slider | Content Injection No login needed |
≤ 3.2.9 Fixed in 3.3.0 |
CVE-2025-47481 |
Patchstack | |
| 4.3 Medium | GS Testimonial Slider | Broken Access Control |
≤ 3.3.0 Fixed in 3.3.1 |
CVE-2025-47467 |
Patchstack | |
| 7.5 High | Slider & Popup Builder by Depicter | SQL Injection Unauthenticated SQL Injection via 's' Parameter No login needed |
≤ 3.6.1 |
CVE-2025-2011 |
Wordfence | |
| 6.1 Medium | Advanced Reorder Image Text Slider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-4188 |
Wordfence | |
| 6.4 Medium | Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder | Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.4.1 |
CVE-2025-3521 |
Wordfence | |
| 4.3 Medium | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed |
≤ 2.4.1 |
CVE-2025-2168 |
Wordfence | |
| 7.1 High | visualslider Sldier | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.1 Fixed in 1.4 |
CVE-2025-23448 |
Patchstack | |
| 9.8 Critical | Saoshyant Slider | PHP Object Injection No login needed |
≤ 3.0 |
CVE-2025-27286 |
Patchstack | |
| 7.1 High | flickr-slideshow-wrapper | Cross-Site Scripting No login needed |
≤ 5.4.6 |
CVE-2025-27309 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.