WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 251–300 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) ≤ 2.7.7.25 Fixed in 2.7.7.26 CVE-2025-47677 Patchstack
6.5 Medium Awesome Gallery Plugin awesome-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-47632 Patchstack
9.1 Critical BEAF Plugin beaf-before-and-after-gallery Arbitrary File Upload ≤ 4.6.10 Fixed in 4.6.11 CVE-2025-47549 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2025-47521 Patchstack
5.9 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting ≤ 5.2.7 Fixed in 5.2.8 CVE-2025-47449 Patchstack
6.5 Medium Awesome Wp Image Gallery Plugin awesome-wp-image-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-46476 Patchstack
6.4 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id' ≤ 2.4.6 CVE-2025-3458 Wordfence
7.1 High WordPress Photo Gallery – Image Gallery Plugin photo-image-gallery Cross-Site Scripting Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-27291 Patchstack
7.1 High T&P Gallery Slider Plugin tp-gallery-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-32527 Patchstack
7.1 High GB Gallery Slideshow Plugin gb-gallery-slideshow Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-32649 Patchstack
4.3 Medium InPost Gallery Plugin inpost-gallery Cross-Site Request Forgery No login needed ≤ 2.1.4.3 Fixed in 2.1.4.4 CVE-2025-26903 Patchstack
7.1 High Global Gallery Plugin global-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8.0 CVE-2025-22263 Patchstack
7.1 High ZooEffect Plugin 1-jquery-photo-gallery-slideshow-flash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.11 CVE-2025-26954 Patchstack
6.1 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter No login needed ≤ 1.8.34 CVE-2025-2269 Wordfence
7.1 High Smart Product Gallery Slider Plugin smart-product-gallery-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.4 CVE-2025-31392 Patchstack
6.5 Medium SimpLy Gallery Plugin simply-gallery-block Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.2.5 Fixed in 3.2.6 CVE-2025-32176 Patchstack
7.6 High Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member SQL Injection ≤ 1.1.3 CVE-2025-32121 Patchstack
6.4 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library ≤ 2.10.1 CVE-2024-9416 Wordfence
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
4.3 Medium GB Gallery Slideshow Plugin gb-gallery-slideshow Broken Access Control ≤ 1.3 CVE-2025-31732 Patchstack
6.5 Medium Gallery – Photo Albums Plugin easy-media-gallery Cross-Site Scripting Photo Albums Plugin plugin <= 1.3.170 - Stored Cross Site Scripting (XSS) ≤ 1.3.170 CVE-2025-31586 Patchstack
7.1 High Rio Video Gallery Plugin rio-video-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3.6 CVE-2025-31566 Patchstack
6.5 Medium JetProductGallery Plugin jet-woo-product-gallery Cross-Site Scripting ≤ 2.1.22 Fixed in 2.1.22.1 CVE-2025-31412 Patchstack
6.1 Medium Photo Gallery Plugin photo-gallery Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.8.34 Fixed in 1.8.34 CVE-2025-0613 WPScan
7.1 High ULTIMATE VIDEO GALLERY Plugin ultimate-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-22566 Patchstack
6.5 Medium YouTube SimpleGallery Plugin youtube-simplegallery Cross-Site Scripting ≤ 2.0.6 CVE-2025-31453 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
7.1 High NextGEN Gallery Voting Plugin nextgen-gallery-voting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 CVE-2025-28869 Patchstack
7.1 High Picture Gallery Plugin picture-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-26581 Patchstack
6.5 Medium Gallery for Social Photo Plugin feed-instagram-lite Cross-Site Scripting ≤ 1.0.0.35 Fixed in 1.0.0.37 CVE-2025-26742 Patchstack
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1203 WPScan
3.5 Low Slider, Gallery, Carousel by MetaSlider Plugin Cross-Site Scripting Editor+ Stored XSS < 3.95.0 Fixed in 3.95.0 CVE-2025-1062 WPScan
3.5 Low Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.33 Fixed in 1.8.33 CVE-2024-13124 WPScan
6.4 Medium Gallery Styles Plugin gallery-styles Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 CVE-2025-1783 Wordfence
4.3 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Broken Access Control Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates ≤ 2.4.29 CVE-2024-12114 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size ≤ 2.4.29 CVE-2024-12119 Wordfence
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
7.1 High SW Plus Plugin shalom-world-media-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-25108 Patchstack
7.1 High Easy Gallery Plugin simple-gallery-odihost Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23487 Patchstack
7.1 High Attach Gallery Posts Plugin attach-gallery-posts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-23441 Patchstack
7.2 High Album Gallery – WordPress Gallery Plugin new-album-gallery PHP Object Injection WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta ≤ 1.6.3 CVE-2024-13833 Wordfence
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
6.4 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-1757 Wordfence
5.1 Medium FooGallery - Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS) No login needed 2.4.29 CVE-2025-22624 Fluid Attacks
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.6.0 CVE-2024-6261 Wordfence
7.1 High Tribulant Gallery Voting Plugin gallery-voting Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 Fixed in 1.3 CVE-2025-26931 Patchstack
3.5 Low NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.9 Fixed in 3.59.9 CVE-2024-10545 WPScan
7.1 High Add Linked Images To Gallery Plugin add-linked-images-to-gallery-v01 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-27277 Patchstack
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
9.8 Critical Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection Image Slider, Video Slider Plugin <= 3.94.0 - PHP Object Injection No login needed ≤ 3.94.0 Fixed in 3.95.0 CVE-2025-26763 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only