WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 351–400 of 525 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Video Gallery – YouTube Gallery | Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2023-25988 |
Patchstack | |
| 5.4 Medium | Robo Gallery | Broken Access Control Auth. Broken Access Control |
≤ 3.2.9 Fixed in 3.2.11 |
CVE-2022-45841 |
Patchstack | |
| 6.1 Medium | Video & Photo Gallery for Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.1 |
CVE-2024-12162 |
Wordfence | |
| 7.7 High | Best WordPress Gallery Plugin – FooGallery | Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal |
≤ 2.4.26 |
CVE-2023-6947 |
Wordfence | |
| 5.3 Medium | Album and Image Gallery plus Lightbox | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2023-25060 |
Patchstack | |
| 8.8 High | Gallery | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.3 |
CVE-2024-11501 |
Wordfence | |
| 6.1 Medium | Folder Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting No login needed |
≤ 1.7.4 |
CVE-2024-11823 |
Wordfence | |
| 7.2 High | YouTube Gallery and Vimeo Gallery | SQL Injection Authenticated (Administrator+) SQL Injection |
≤ 2.4.2 |
CVE-2024-10247 |
Wordfence | |
| 4.4 Medium | Video Gallery | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 2.4.1 |
CVE-2024-9769 |
Wordfence | |
| 6.4 Medium | WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout | Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.8.8 |
CVE-2024-11453 |
Wordfence | |
| 7.1 High | AI Responsive Gallery Album | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2024-52467 |
Patchstack | |
| 6.5 Medium | Elementor Image Gallery | Cross-Site Scripting |
≤ 1.0.5 Fixed in 1.0.6 |
CVE-2024-53744 |
Patchstack | |
| 5.9 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-53788 |
Patchstack | |
| 4.8 Medium | Photo Gallery by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.8.31 Fixed in 1.8.31 |
CVE-2024-10704 |
WPScan | |
| 9.8 Critical | Contest Gallery | Privilege Escalation Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover No login needed |
≤ 24.0.7 |
CVE-2024-11103 |
Wordfence | |
| 6.4 Medium | BNE Gallery Extended | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode |
≤ 1.2.1 |
CVE-2024-11119 |
Wordfence | |
| 6.3 Medium | InPost Gallery | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template |
≤ 2.1.4.2 |
CVE-2024-11002 |
Wordfence | |
| 4.8 Medium | NextGEN Gallery | Cross-Site Scripting Admin+ Stored XSS |
< 3.59.5 Fixed in 3.59.5 |
CVE-2024-6393 |
WPScan | |
| 5.5 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 3.2.4.2 |
CVE-2024-10034 |
Wordfence | |
| 7.2 High | Grid View Gallery | PHP Object Injection Authenticated (Editor+) PHP Object Injection |
≤ 1.0 |
CVE-2024-11409 |
Wordfence | |
| 6.5 Medium | drop in image slideshow gallery | Cross-Site Scripting |
≤ 12.0 |
CVE-2024-51914 |
Patchstack | |
| 9.8 Critical | Lis Video Gallery | PHP Object Injection No login needed |
≤ 0.2.1 |
CVE-2024-52430 |
Patchstack | |
| 6.1 Medium | Gallery Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.58 |
CVE-2024-10875 |
Wordfence | |
| 10.0 Critical | Devexhub Gallery | Arbitrary File Upload No login needed |
≤ 2.0.1 |
CVE-2024-52373 |
Patchstack | |
| 10.0 Critical | HB AUDIO GALLERY | Arbitrary File Upload No login needed |
≤ 3.0 |
CVE-2024-51790 |
Patchstack | |
| 7.1 High | Responsive Flickr Gallery | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3.1 |
CVE-2024-51630 |
Patchstack | |
| 8.5 High | Easy Gallery | SQL Injection |
≤ 1.4 |
CVE-2024-51570 |
Patchstack | |
| 5.3 Medium | Video Gallery for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed |
≤ 1.31 |
CVE-2024-10535 |
Wordfence | |
| 9.8 Critical | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | SQL Injection Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection No login needed |
≤ 24.0.3 |
CVE-2024-10687 |
Wordfence | |
| 4.4 Medium | Photo Gallery by 10Web | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.8.30 |
CVE-2024-9878 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget |
≤ 5.10.1 |
CVE-2024-10310 |
Wordfence | |
| 4.3 Medium | Envira Photo Gallery | Cross-Site Request Forgery CSRF leading to notice dismissal |
≤ 1.8.7.3 Fixed in 1.8.8 |
CVE-2024-37095 |
Patchstack | |
| 6.5 Medium | WP Social Feed Gallery | Broken Access Control No login needed |
≤ 4.3.9 Fixed in 4.4.0 |
CVE-2024-39640 |
Patchstack | |
| 4.3 Medium | Envira Photo Gallery | Broken Access Control |
≤ 1.8.14 Fixed in 1.8.15 |
CVE-2024-43925 |
Patchstack | |
| 7.1 High | CWD 3D Image Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2024-49632 |
Patchstack | |
| 5.9 Medium | Robo Gallery | Cross-Site Scripting |
≤ 3.2.21 Fixed in 3.2.22 |
CVE-2024-49696 |
Patchstack | |
| 5.3 Medium | Responsive Lightbox | Broken Access Control No login needed |
≤ 2.4.7 Fixed in 2.4.8 |
CVE-2024-43924 |
Patchstack | |
| 4.3 Medium | Photo Gallery Builder | Broken Access Control Broken Access Control to Notice Dismissal |
≤ 3.0 |
CVE-2024-49325 |
Patchstack | |
| 4.9 Medium | Photo Gallery Slideshow & Masonry Tiled Gallery | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.3 |
CVE-2019-25218 |
Wordfence | |
| 6.5 Medium | Lightbox slider – Responsive Lightbox Gallery | Cross-Site Scripting |
≤ 1.10.6 |
CVE-2024-49280 |
Patchstack | |
| 5.9 Medium | Responsive Lightbox | Cross-Site Scripting |
≤ 2.4.8 Fixed in 2.4.9 |
CVE-2024-49282 |
Patchstack | |
| 6.5 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-49302 |
Patchstack | |
| 6.5 Medium | WordPress Gallery Plugin – Limb Image Gallery | Path Traversal Arbitrary File Download |
≤ 1.5.7 |
CVE-2024-49258 |
Patchstack | |
| 9.9 Critical | WordPress Gallery Plugin – Limb Image Gallery | Arbitrary File Upload |
≤ 1.5.7 |
CVE-2024-49260 |
Patchstack | |
| 4.4 Medium | ImagePress - Image Gallery | Cross-Site Scripting Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.2.2 |
CVE-2024-9776 |
Wordfence | |
| 4.3 Medium | ImagePress - Image Gallery | Broken Access Control Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update |
≤ 1.2.2 |
CVE-2024-9824 |
Wordfence | |
| 4.3 Medium | ImagePress – Image Gallery | Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.2.2 |
CVE-2024-9778 |
Wordfence | |
| 4.8 Medium | Photo Gallery by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.8.28 Fixed in 1.8.28 |
CVE-2024-5968 |
WPScan | |
| 4.3 Medium | Photo Gallery, Images, Slider in Rbs Image Gallery | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure |
≤ 3.2.21 |
CVE-2024-8431 |
Wordfence | |
| 5.9 Medium | Photo Gallery by 10Web | Cross-Site Scripting |
≤ 1.8.27 Fixed in 1.8.28 |
CVE-2024-44043 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.