WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 251–300 of 343 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget ≤ 6.0.3 CVE-2024-8742 Wordfence
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
4.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS < 1.8.15 Fixed in 1.8.15 CVE-2024-3899 WPScan
5.3 Medium Contest Gallery Plugin contest-gallery Information Disclosure Unauthenticated Comment UserID And IP address Disclosure No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-43283 Patchstack
6.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via File Upload ≤ 2.4.7 CVE-2024-6870 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets ≤ 5.7.2 CVE-2024-7247 Wordfence
5.9 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting ≤ 1.15.6 Fixed in 1.15.7 CVE-2024-43152 Patchstack
5.9 Medium NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) ≤ 3.59.3 Fixed in 3.59.4 CVE-2024-39627 Patchstack
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title ≤ 3.2.19 CVE-2024-3896 Wordfence
6.4 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode ≤ 3.7.1 CVE-2024-6629 Wordfence
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Gallery Slideshow Plugin gallery-slideshow Cross-Site Scripting ≤ 1.4.1 CVE-2024-37246 Patchstack
5.9 Medium NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.3 Fixed in 3.59.3 CVE-2024-5442 WPScan
6.8 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Contributor+ Stored XSS < 3.6.0 Fixed in 3.6.0 CVE-2024-3710 WPScan
6.8 Medium Smart Image Gallery Plugin Cross-Site Request Forgery Update/Delete Google API Key via CSRF < 1.0.19 Fixed in 1.0.19 CVE-2024-3632 WPScan
6.4 Medium Feeds for YouTube (YouTube video, channel, and gallery plugin) Plugin feeds-for-youtube Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-6256 Wordfence
5.4 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2024-37542 Patchstack
6.4 Medium Mixed Media Gallery Blocks Plugin simply-gallery-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters ≤ 3.2.1 CVE-2024-5424 Wordfence
6.4 Medium Portfolio Gallery – Image Gallery Plugin portfolio-filter-gallery Cross-Site Scripting Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 1.6.4 CVE-2024-6262 Wordfence
5.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget ≤ 2.1.5 CVE-2024-6283 Wordfence
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.5.4 CVE-2024-5036 Wordfence
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title ≤ 3.2.19 CVE-2024-3894 Wordfence
6.4 Medium MaxGalleria Plugin maxgalleria Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thumb Shortcode ≤ 6.4.4 CVE-2024-5970 Wordfence
6.4 Medium Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Authenticated (Contributor+) Arbitrary File Inclusion via Shortcode ≤ 1.3.13 CVE-2024-4551 Wordfence
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL ≤ 2.4.15 CVE-2024-2122 Wordfence
6.3 Medium FooGallery Plugin Cross-Site Scripting Author+ Stored XSS < 2.4.15 Fixed in 2.4.15 CVE-2024-2762 WPScan
4.3 Medium ACF Photo Gallery Field Plugin navz-photo-gallery Broken Access Control ≤ 2.6 Fixed in 2.7 CVE-2024-23518 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.25 Fixed in 1.8.26 CVE-2024-35628 Patchstack
4.3 Medium Album Gallery – WordPress Gallery Plugin new-album-gallery Broken Access Control WordPress Gallery plugin <= 1.5.7 - Broken Access Control ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-35720 Patchstack
4.3 Medium Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery Plugin new-image-gallery Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-35721 Patchstack
4.3 Medium Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin slider-responsive-slideshow Broken Access Control Image slider, Gallery slideshow plugin <= 1.4.0 - Broken Access Control ≤ 1.4.0 Fixed in 1.4.2 CVE-2024-35722 Patchstack
4.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-31252 Patchstack
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control ≤ 3.5.2 Fixed in 3.6.0 CVE-2024-31248 Patchstack
6.8 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function ≤ 1.8.23 CVE-2024-5481 Wordfence
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG ≤ 1.8.23 CVE-2024-5426 Wordfence
6.5 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0 CVE-2024-4194 Wordfence
6.5 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting ≤ 1.5.11 Fixed in 1.5.12 CVE-2024-34759 Patchstack
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block ≤ 2.12.8 CVE-2024-1815 Wordfence
5.3 Medium YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin youtube-showcase Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed ≤ 3.3.6 CVE-2024-3268 Wordfence
6.0 Medium Unite Gallery Lite Plugin unite-gallery-lite Local File Inclusion ≤ 1.7.59 Fixed in 1.7.60 CVE-2023-33310 Patchstack
4.3 Medium Nextgen Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.1 Fixed in 3.59.1 CVE-2024-2744 WPScan
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-site Scriping via 'Sina Particle Layer' ≤ 3.5.3 CVE-2024-4373 Wordfence
6.4 Medium Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter ≤ 3.3.2 CVE-2024-4363 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Cross-Site Scripting ≤ 3.5.3 CVE-2024-4333 Wordfence
6.4 Medium Gallery Block (Meow Gallery) Plugin meow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.3 CVE-2024-4386 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify ≤ 2.5.0 CVE-2024-3989 Wordfence
5.9 Medium Featured Content Gallery Plugin featured-content-gallery Cross-Site Scripting ≤ 3.2.0 CVE-2024-34424 Patchstack
4.8 Medium Ungallery Plugin ungallery Cross-Site Scripting Stored XSS via CSRF ≤ 2.2.4 CVE-2024-3582 WPScan
4.3 Medium Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery Plugin new-video-gallery Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-34377 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only