WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 351–400 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Video Gallery – YouTube Gallery Plugin gallery-videos Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2023-25988 Patchstack
5.4 Medium Robo Gallery Plugin robo-gallery Broken Access Control Auth. Broken Access Control ≤ 3.2.9 Fixed in 3.2.11 CVE-2022-45841 Patchstack
6.1 Medium Video & Photo Gallery for Ultimate Member Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2024-12162 Wordfence
7.7 High Best WordPress Gallery Plugin – FooGallery Plugin Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.26 CVE-2023-6947 Wordfence
5.3 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2023-25060 Patchstack
8.8 High Gallery Plugin multi-gallery PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.3 CVE-2024-11501 Wordfence
6.1 Medium Folder Gallery Plugin folder-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2024-11823 Wordfence
7.2 High YouTube Gallery and Vimeo Gallery Plugin gallery-videos SQL Injection Authenticated (Administrator+) SQL Injection ≤ 2.4.2 CVE-2024-10247 Wordfence
4.4 Medium Video Gallery Plugin video-wc-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2024-9769 Wordfence
6.4 Medium WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout Plugin gs-pinterest-portfolio Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.8 CVE-2024-11453 Wordfence
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.31 Fixed in 1.8.31 CVE-2024-10704 WPScan
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover No login needed ≤ 24.0.7 CVE-2024-11103 Wordfence
6.4 Medium BNE Gallery Extended Plugin bne-gallery-extended Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode ≤ 1.2.1 CVE-2024-11119 Wordfence
6.3 Medium InPost Gallery Plugin inpost-gallery Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template ≤ 2.1.4.2 CVE-2024-11002 Wordfence
4.8 Medium NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.5 Fixed in 3.59.5 CVE-2024-6393 WPScan
5.5 Medium Mixed Media Gallery Blocks Plugin Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 3.2.4.2 CVE-2024-10034 Wordfence
7.2 High Grid View Gallery Plugin grid-view-gallery PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 1.0 CVE-2024-11409 Wordfence
6.5 Medium drop in image slideshow gallery Plugin drop-in-image-slideshow-gallery Cross-Site Scripting ≤ 12.0 CVE-2024-51914 Patchstack
9.8 Critical Lis Video Gallery Plugin lis-video-gallery PHP Object Injection No login needed ≤ 0.2.1 CVE-2024-52430 Patchstack
6.1 Medium Gallery Manager Plugin fancy-gallery Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.58 CVE-2024-10875 Wordfence
10.0 Critical Devexhub Gallery Plugin devexhub-gallery Arbitrary File Upload No login needed ≤ 2.0.1 CVE-2024-52373 Patchstack
10.0 Critical HB AUDIO GALLERY Plugin hb-audio-gallery Arbitrary File Upload No login needed ≤ 3.0 CVE-2024-51790 Patchstack
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
8.5 High Easy Gallery Plugin simple-gallery-odihost SQL Injection ≤ 1.4 CVE-2024-51570 Patchstack
5.3 Medium Video Gallery for WooCommerce Plugin video-wc-gallery Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed ≤ 1.31 CVE-2024-10535 Wordfence
9.8 Critical Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery SQL Injection Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection No login needed ≤ 24.0.3 CVE-2024-10687 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.8.30 CVE-2024-9878 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
6.5 Medium WP Social Feed Gallery Plugin insta-gallery Broken Access Control No login needed ≤ 4.3.9 Fixed in 4.4.0 CVE-2024-39640 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control ≤ 1.8.14 Fixed in 1.8.15 CVE-2024-43925 Patchstack
7.1 High CWD 3D Image Gallery Plugin cwd-3d-image-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49632 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 3.2.21 Fixed in 3.2.22 CVE-2024-49696 Patchstack
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
5.9 Medium Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2024-49282 Patchstack
6.5 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-49302 Patchstack
6.5 Medium WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Path Traversal Arbitrary File Download ≤ 1.5.7 CVE-2024-49258 Patchstack
9.9 Critical WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Arbitrary File Upload ≤ 1.5.7 CVE-2024-49260 Patchstack
4.4 Medium ImagePress - Image Gallery Plugin image-gallery Cross-Site Scripting Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2.2 CVE-2024-9776 Wordfence
4.3 Medium ImagePress - Image Gallery Plugin image-gallery Broken Access Control Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update ≤ 1.2.2 CVE-2024-9824 Wordfence
4.3 Medium ImagePress – Image Gallery Plugin image-gallery Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.2.2 CVE-2024-9778 Wordfence
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.28 Fixed in 1.8.28 CVE-2024-5968 WPScan
4.3 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure ≤ 3.2.21 CVE-2024-8431 Wordfence
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.27 Fixed in 1.8.28 CVE-2024-44043 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only