WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 301–350 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.7 Medium WP Touch Slider Plugin Cross-Site Scripting Reflected XSS ≤ 2.2 CVE-2024-13627 WPScan
7.6 High WP Airbnb Review Slider Plugin wp-airbnb-review-slider SQL Injection ≤ 3.9 Fixed in 4.0 CVE-2025-26755 Patchstack
4.3 Medium Slide Banners Plugin slide-banners Broken Access Control ≤ 1.3 CVE-2025-25120 Patchstack
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
7.1 High Post Carousel Slider Plugin post-carousel-slider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.1 CVE-2025-23977 Patchstack
6.1 Medium SlideDeck 1 Lite Content Slider Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.4.8 CVE-2024-13224 WPScan
6.4 Medium Gosign – Posts Slider Block Plugin gosign-posts-slider-block Cross-Site Scripting Posts Slider Block <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-13399 Wordfence
6.4 Medium WE – Testimonial Slider Plugin we-testimonial-slider Cross-Site Scripting Testimonial Slider <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5 CVE-2024-13460 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
3.8 Low Crelly Slider Plugin crelly-slider Cross-Site Scripting Admin+ Stored XSS < 1.4.7 Fixed in 1.4.7 CVE-2024-13116 WPScan
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
4.3 Medium Super Block Slider Plugin super-block-slider Broken Access Control ≤ 2.7.9 Fixed in 2.8 CVE-2025-24682 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.16.5 CVE-2024-12043 Wordfence
7.1 High FWD Slider Plugin fwd-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23462 Patchstack
7.1 High Cyber Slider Plugin cyber-new-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23630 Patchstack
5.4 Medium Slides & Presentations Plugin slide Content Injection ≤ 0.0.39 CVE-2025-23919 Patchstack
7.1 High Len Slider Plugin len-slider Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 CVE-2025-23810 Patchstack
7.1 High Slider for Writers Plugin slider-for-writers Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-23692 Patchstack
7.1 High NV Slider Plugin nv-slider Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.6 CVE-2025-23661 Patchstack
7.1 High Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-22750 Patchstack
4.3 Medium WP News Sliders Plugin wp-news-sliders Broken Access Control ≤ 1.0 CVE-2025-22779 Patchstack
6.5 Medium Responsive jQuery Slider Plugin responsive-jquery-slider Cross-Site Scripting ≤ 1.1.1 CVE-2025-22798 Patchstack
6.4 Medium Accordion Slider Lite Plugin accordion-slider-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.1 CVE-2024-11892 Wordfence
7.1 High MG Parallax Slider Plugin mg-parallax-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0. CVE-2025-22330 Patchstack
6.5 Medium Responsive Flickr Slideshow Plugin mobile-friendly-flickr-slideshow Cross-Site Scripting ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-22807 Patchstack
6.5 Medium Slides & Presentations Plugin slide Cross-Site Scripting ≤ 0.0.39 CVE-2025-22511 Patchstack
5.4 Medium Slides & Presentations Plugin slide Broken Access Control ≤ 0.0.39 CVE-2025-22534 Patchstack
7.1 High Smoothness Slider Shortcode Plugin smoothness-slider-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ v1.2.2 CVE-2025-22555 Patchstack
2.7 Low Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10102 WPScan
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
6.4 Medium Meteor Slides Plugin meteor-slides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.7 CVE-2024-12073 Wordfence
6.4 Medium Slider Pro Lite Plugin slider-pro-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-11899 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
7.1 High Gulri Slider Plugin gulri-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2024-56223 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
6.4 Medium Category Post Slider Plugin category-post-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4 CVE-2024-11878 Wordfence
5.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 1.2.7 Fixed in 1.2.7 CVE-2024-11108 WPScan
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
5.4 Medium Ui Slider Filter By Price Plugin ui-slider-filter-by-price Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-54419 Patchstack
6.4 Medium Wp photo text slider 50 Plugin wp-photo-text-slider-50 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.1 CVE-2024-11884 Wordfence
6.4 Medium Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11770 Wordfence
4.3 Medium Slider Pro Plugin sliderpro Broken Access Control ≤ 4.8.6 Fixed in 4.8.7 CVE-2023-41865 Patchstack
5.3 Medium Carousel Slider Plugin carousel-slider Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-41848 Patchstack
4.3 Medium Category Slider for WooCommerce Plugin woo-category-slider-grid Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2023-41132 Patchstack
4.3 Medium Accordion Slider Plugin accordion-slider Broken Access Control ≤ 1.9.6 Fixed in 1.9.7 CVE-2023-40331 Patchstack
5.3 Medium Accordion and Accordion Slider Plugin accordion-and-accordion-slider Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2023-39996 Patchstack
7.5 High Easing Slider Plugin easing-slider Broken Access Control Plugin Settings Reset No login needed ≤ 3.0.8 CVE-2023-30490 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only