WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 401–450 of 525 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Scripting ≤ 1.8.3 Fixed in 1.8.4 CVE-2024-47376 Patchstack
5.9 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.39 Fixed in 1.0.0.41 CVE-2024-47623 Patchstack
8.8 High WP Easy Gallery Plugin wp-easy-gallery SQL Injection Authenticated (Contributor+) SQL Injection via key Parameter ≤ 4.8.5 CVE-2024-9018 Wordfence
5.3 Medium Sight – Professional Image Gallery and Portfolio Plugin sight Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed ≤ 1.1.2 CVE-2024-9025 Wordfence
9.9 Critical WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection ≤ 4.8.5 CVE-2024-8436 Wordfence
4.3 Medium WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery Broken Access Control WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation ≤ 4.8.5 CVE-2024-8437 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget ≤ 6.0.3 CVE-2024-8742 Wordfence
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
4.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS < 1.8.15 Fixed in 1.8.15 CVE-2024-3899 WPScan
5.3 Medium Contest Gallery Plugin contest-gallery Information Disclosure Unauthenticated Comment UserID And IP address Disclosure No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-43283 Patchstack
6.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via File Upload ≤ 2.4.7 CVE-2024-6870 Wordfence
8.5 High Unite Gallery Lite Plugin unite-gallery-lite SQL Injection ≤ 1.7.62 CVE-2024-43207 Patchstack
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets ≤ 5.7.2 CVE-2024-7247 Wordfence
5.9 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting ≤ 1.15.6 Fixed in 1.15.7 CVE-2024-43152 Patchstack
5.9 Medium NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) ≤ 3.59.3 Fixed in 3.59.4 CVE-2024-39627 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-39631 Patchstack
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title ≤ 3.2.19 CVE-2024-3896 Wordfence
6.4 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode ≤ 3.7.1 CVE-2024-6629 Wordfence
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Gallery Slideshow Plugin gallery-slideshow Cross-Site Scripting ≤ 1.4.1 CVE-2024-37246 Patchstack
5.9 Medium NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.3 Fixed in 3.59.3 CVE-2024-5442 WPScan
6.8 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Contributor+ Stored XSS < 3.6.0 Fixed in 3.6.0 CVE-2024-3710 WPScan
6.8 Medium Smart Image Gallery Plugin Cross-Site Request Forgery Update/Delete Google API Key via CSRF < 1.0.19 Fixed in 1.0.19 CVE-2024-3632 WPScan
6.4 Medium Feeds for YouTube (YouTube video, channel, and gallery plugin) Plugin feeds-for-youtube Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-6256 Wordfence
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
5.4 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2024-37542 Patchstack
6.4 Medium Mixed Media Gallery Blocks Plugin simply-gallery-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters ≤ 3.2.1 CVE-2024-5424 Wordfence
6.4 Medium Portfolio Gallery – Image Gallery Plugin portfolio-filter-gallery Cross-Site Scripting Image Gallery Plugin <= 1.6.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 1.6.4 CVE-2024-6262 Wordfence
5.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget ≤ 2.1.5 CVE-2024-6283 Wordfence
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.5.4 CVE-2024-5036 Wordfence
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title ≤ 3.2.19 CVE-2024-3894 Wordfence
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
8.8 High Photo Video Gallery Master Plugin photo-video-gallery-master PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.5.3 CVE-2024-5724 Wordfence
9.3 Critical WordPress Picture / Portfolio / Media Gallery Plugin nimble-portfolio Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.0.1 CVE-2024-5021 Wordfence
6.4 Medium MaxGalleria Plugin maxgalleria Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thumb Shortcode ≤ 6.4.4 CVE-2024-5970 Wordfence
6.4 Medium Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Authenticated (Contributor+) Arbitrary File Inclusion via Shortcode ≤ 1.3.13 CVE-2024-4551 Wordfence
9.8 Critical Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.13 CVE-2024-4258 Wordfence
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL ≤ 2.4.15 CVE-2024-2122 Wordfence
6.3 Medium FooGallery Plugin Cross-Site Scripting Author+ Stored XSS < 2.4.15 Fixed in 2.4.15 CVE-2024-2762 WPScan
8.1 High Slideshow Gallery LITE Plugin slideshow-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.8.1 CVE-2024-5543 Wordfence
4.3 Medium ACF Photo Gallery Field Plugin navz-photo-gallery Broken Access Control ≤ 2.6 Fixed in 2.7 CVE-2024-23518 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.25 Fixed in 1.8.26 CVE-2024-35628 Patchstack
4.3 Medium Album Gallery – WordPress Gallery Plugin new-album-gallery Broken Access Control WordPress Gallery plugin <= 1.5.7 - Broken Access Control ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-35720 Patchstack
4.3 Medium Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery Plugin new-image-gallery Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-35721 Patchstack
4.3 Medium Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin slider-responsive-slideshow Broken Access Control Image slider, Gallery slideshow plugin <= 1.4.0 - Broken Access Control ≤ 1.4.0 Fixed in 1.4.2 CVE-2024-35722 Patchstack
8.5 High Contest Gallery Plugin contest-gallery Arbitrary File Deletion ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-32778 Patchstack
4.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-31252 Patchstack
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control ≤ 3.5.2 Fixed in 3.6.0 CVE-2024-31248 Patchstack
8.5 High Responsive Image Gallery, Gallery Album Plugin gallery-album SQL Injection Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 CVE-2024-35750 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only