WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 351–400 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Depicter Slider Plugin depicter Broken Access Control ≤ 1.9.0 Fixed in 1.9.1 CVE-2022-47176 Patchstack
5.3 Medium Trending/Popular Post Slider and Widget Plugin wp-trending-post-slider-and-widget Broken Access Control No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2022-46846 Patchstack
6.4 Medium WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more Plugin gs-books-showcase Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-11766 Wordfence
6.4 Medium WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more Plugin gs-portfolio Cross-Site Scripting A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.3 CVE-2024-11765 Wordfence
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
6.4 Medium Horizontal scroll image slideshow Plugin horizontal-scroll-image-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.1 CVE-2024-11442 Wordfence
5.3 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.7 CVE-2023-25703 Patchstack
6.4 Medium Depicter — Popup & Slider Builder Plugin depicter Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.2.1 CVE-2024-4633 Wordfence
8.8 High Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Local File Inclusion Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion ≤ 3.3.3 CVE-2024-11429 Wordfence
7.1 High Infinite Slider Plugin infinite-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-52461 Patchstack
5.9 Medium Meteor Slides Plugin meteor-slides Cross-Site Scripting ≤ 1.5.7 CVE-2024-52493 Patchstack
5.9 Medium Image horizontal reel scroll slideshow Plugin image-horizontal-reel-scroll-slideshow Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 13.4 CVE-2024-52492 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
6.5 Medium Vertical Carousel Plugin vertical-carousel-slider Cross-Site Scripting ≤ 1.0.2 CVE-2024-53756 Patchstack
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.5.0 Fixed in 4.5.0 CVE-2024-10896 WPScan
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Author+ Stored XSS < 4.5.0 Fixed in 4.5.0 CVE-2024-10473 WPScan
6.4 Medium Tribute Testimonials – WordPress Testimonial Grid/Slider Plugin tribute-testimonial-gridslider Cross-Site Scripting WordPress Testimonial Grid/Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-10886 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
7.1 High SH Slideshow Plugin sh-slideshow Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.3 CVE-2024-51632 Patchstack
6.5 Medium Luzuk Slider Plugin luzuk-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.5 CVE-2024-51834 Patchstack
6.5 Medium NV Slider Plugin nv-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.6 CVE-2024-51887 Patchstack
6.5 Medium Magic Slider Plugin magic-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2024-51896 Patchstack
6.5 Medium drop in image slideshow gallery Plugin drop-in-image-slideshow-gallery Cross-Site Scripting ≤ 12.0 CVE-2024-51914 Patchstack
6.5 Medium Testimonial Slider Shortcode Plugin testimonial-slider-shortcode Cross-Site Scripting ≤ 1.1.9 CVE-2024-51925 Patchstack
6.5 Medium Kings Tab Slider Plugin kings-tab-slider Cross-Site Scripting ≤ 1.0 CVE-2024-51932 Patchstack
6.5 Medium OS BXSlider Plugin os-bxslider Cross-Site Scripting ≤ 2.6 CVE-2024-52342 Patchstack
9.9 Critical B-Banner Slider Plugin b-banner-slider Arbitrary File Upload ≤ 1.1 CVE-2024-52405 Patchstack
7.3 High Uix Slideshow Plugin uix-slideshow Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.5 CVE-2024-9839 Wordfence
6.4 Medium Social Proof (Testimonials) Slider Plugin social-proof-testimonials-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spslider-block Shortcode ≤ 2.2.4 CVE-2024-8985 Wordfence
6.5 Medium BU Slideshow Plugin bu-slideshow Cross-Site Scripting ≤ 2.3.10 CVE-2024-52351 Patchstack
7.1 High Wp Slide Categorywise Plugin wp-slide-categorywise Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51690 Patchstack
7.1 High Team Showcase and Slider – Team Members Builder Plugin team-showcase-ultimate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51763 Patchstack
4.3 Medium Content Slider Block – Create fully functional slider with Gutenberg block Plugin content-slider-block Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure ≤ 3.1.5 CVE-2024-10667 Wordfence
6.4 Medium Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget ≤ 3.15.18 CVE-2024-8442 Wordfence
4.3 Medium Social Slider Feed Plugin instagram-slider-widget Broken Access Control ≤ 2.2.2 Fixed in 2.2.5 CVE-2024-43215 Patchstack
5.3 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 3.2.2 Fixed in 3.5.0 CVE-2024-47359 Patchstack
7.1 High Banner Slider Plugin banner-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2024-49635 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 3.2.21 Fixed in 3.2.22 CVE-2024-49696 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
7.1 High All in One Slider Plugin all-in-one-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-49323 Patchstack
7.1 High jLayer Parallax Slider Plugin jlayer-parallax-slider-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49334 Patchstack
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.6 High Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-5429 WPScan
7.5 High MaxSlider Plugin maxslider Local File Inclusion ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-47351 Patchstack
6.4 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting Authenticted (Contributor+) Stored Cross-Site Scripting via HTML Attribute ≤ 1.9.11 CVE-2024-9582 Wordfence
4.3 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure ≤ 3.2.21 CVE-2024-8431 Wordfence
6.5 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-47307 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only