WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 301–350 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Admin+ Stored XSS < 2.7.4 Fixed in 2.7.4 CVE-2024-13314 WPScan
6.4 Medium 3D Photo Gallery Plugin 3d-photo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-13751 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.5 Medium Categorized Gallery Plugin categorized-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.0 CVE-2024-13676 Wordfence
5.9 Medium Gallery Plugin gallery Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-26778 Patchstack
7.1 High Singsys -Awesome Gallery Plugin awesome-gallery-singsys Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23748 Patchstack
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget ≤ 2.1.8 CVE-2024-13644 Wordfence
5.4 Medium Global Gallery - WordPress Responsive Gallery Plugin Arbitrary Shortcode Execution WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 9.1.5 CVE-2024-13814 Wordfence
6.5 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-25080 Patchstack
6.5 Medium NextGen Cooliris Gallery Plugin nextgen-cooliris-gallery Cross-Site Scripting ≤ 0.7 CVE-2025-25091 Patchstack
7.6 High Contest Gallery Plugin contest-gallery SQL Injection ≤ 25.1.0 Fixed in 25.1.2 CVE-2025-22693 Patchstack
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.24 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.24 Fixed in 2.7.7.25 CVE-2025-24707 Patchstack
6.5 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Broken Access Control Responsive Photo Gallery plugin <= 1.0.5 - Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.2 CVE-2025-24697 Patchstack
6.4 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13400 Wordfence
5.3 Medium picu Plugin picu Broken Access Control Online Photo Proofing Gallery plugin <= 2.4.0 - Broken Access Control No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24590 Patchstack
6.4 Medium Masy Gallery Plugin masy-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13586 Wordfence
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
7.1 High FooGallery Captions Plugin foogallery-captions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23889 Patchstack
6.4 Medium Simple Gallery with Filter Plugin simple-gallery-with-filter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-13583 Wordfence
7.1 High Good Old Gallery Plugin good-old-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-23959 Patchstack
9.1 Critical WP Load Gallery Plugin wp-load-gallery Arbitrary File Upload ≤ 2.1.6 CVE-2025-23942 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
7.1 High Rio Photo Gallery Plugin rio-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23597 Patchstack
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.19 CVE-2024-13584 Wordfence
6.4 Medium Picture Gallery – Frontend Image Uploads, AJAX Photo List Plugin picture-gallery Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode ≤ 1.5.22 CVE-2024-12696 Wordfence
6.5 Medium Gallery: Hybrid – Advanced Visual Gallery Plugin hybrid-gallery Cross-Site Scripting Advanced Visual Gallery plugin <= 1.4.0.2 - Cross Site Scripting (XSS) ≤ 1.4.0.2 CVE-2025-23951 Patchstack
7.1 High Gallery Plugin wordpress-gallery-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23842 Patchstack
4.3 Medium AI Responsive Gallery Album Plugin ai-responsive-gallery-album Broken Access Control ≤ 1.4 CVE-2025-23785 Patchstack
7.1 High Photo Gallery – Image Gallery by Ape Plugin gallery-images-ape Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.8 CVE-2025-22317 Patchstack
6.5 Medium Gallery and Lightbox Plugin gallery-and-lightbox Cross-Site Scripting ≤ 1.0.14 CVE-2025-22797 Patchstack
6.1 Medium Image Gallery – Responsive Photo Gallery Plugin awesome-responsive-photo-gallery Cross-Site Scripting Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting No login needed ≤ 1.0.5 CVE-2024-12403 Wordfence
8.8 High Modula Image Gallery Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.11.10 CVE-2024-12853 Wordfence
6.5 Medium Justified Image Gallery Plugin justified-image-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-22518 Patchstack
5.4 Medium ST Gallery WP Plugin st-gallery-wp Broken Access Control Settings Change ≤ 1.0.8 CVE-2025-22543 Patchstack
7.1 High BVD Easy Gallery Manager Plugin bvd-easy-gallery-manager Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-22353 Patchstack
2.7 Low Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10102 WPScan
6.4 Medium WP Youtube Gallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9 CVE-2024-12590 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
5.9 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-56237 Patchstack
4.3 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2023-45631 Patchstack
7.1 High odPhotogallery Plugin od-photogallery-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.3 CVE-2024-56036 Patchstack
6.1 Medium Exhibit to WP Gallery Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.0.2 CVE-2024-12096 WPScan
6.4 Medium Portfolio – Filterable Masonry Portfolio Gallery for Professionals Plugin portfolio-pro Cross-Site Scripting Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-11900 Wordfence
9.9 Critical Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Arbitrary File Upload ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-54370 Patchstack
9.3 Critical Nabz Image Gallery Plugin nabz-image-gallery SQL Injection No login needed ≤ v1.00 CVE-2024-55981 Patchstack
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Justified Gallery Plugin justified-gallery Broken Access Control ≤ 1.7.3 Fixed in 1.8.0 CVE-2023-40213 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.15 Fixed in 1.8.16 CVE-2023-33995 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only