WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 401–450 of 562 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Scripting ≤ 1.8.3 Fixed in 1.8.4 CVE-2024-47376 Patchstack
5.9 Medium Depicter Slider Plugin depicter Cross-Site Scripting ≤ 3.2.2 Fixed in 3.5.0 CVE-2024-47381 Patchstack
5.9 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.39 Fixed in 1.0.0.41 CVE-2024-47623 Patchstack
6.5 Medium Logo Carousel – Clients logo carousel for WP Plugin responsive-client-logo-carousel-slider Cross-Site Scripting Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) ≤ 1.2 Fixed in 1.3.0 CVE-2024-47631 Patchstack
6.4 Medium XO Slider Plugin xo-liteslider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.8.6 CVE-2024-8324 Wordfence
6.4 Medium Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode ≤ 3.3.1 CVE-2024-8989 Wordfence
6.4 Medium Slider Revolution Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 6.7.18 CVE-2024-8107 Wordfence
4.8 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Admin+ Stored XSS < 1.2.59 Fixed in 1.2.59 CVE-2024-8283 WPScan
4.3 Medium Slider by Supsystic Plugin slider-by-supsystic Broken Access Control Broken Access Control vulnerability on multiple WordPress plugins by Supsystic ≤ 1.8.6, ≤ 2.2.9 Fixed in 1.8.7 CVE-2024-47330 Patchstack
6.5 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated Local File Inclusion ≤ 1.9.10 Fixed in 1.10.0 CVE-2024-44048 Patchstack
7.1 High Product Slider for WooCommerce Plugin woocommerce-products-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.50 Fixed in 1.13.51 CVE-2024-45459 Patchstack
4.8 Medium Carousel Slider Plugin carousel-slider Cross-Site Scripting Editor+ Stored XSS < 2.2.4 Fixed in 2.2.4 CVE-2024-6850 WPScan
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
4.8 Medium GS Logo Slider Lite Plugin Cross-Site Scripting Admin+ Stored XSS < 3.6.9 Fixed in 3.6.9 CVE-2024-7716 WPScan
6.4 Medium Slider comparison image before and after Plugin slider-comparison-image-before-and-after Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.8.3 CVE-2024-8543 Wordfence
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters ≤ 1.13.5 CVE-2024-4401 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence
6.4 Medium Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Plugin logo-showcase-ultimate Cross-Site Scripting Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.4.1 CVE-2024-8046 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
8.5 High Timeline and History slider Plugin timeline-and-history-slider Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43232 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.6.4 Fixed in 2.0.0 CVE-2024-43342 Patchstack
6.1 Medium Slideshow, Image Slider by 2J Plugin 2j-slideshow Cross-Site Scripting Reflected Cross-Site Scripting via 'post' No login needed ≤ 1.3.54 CVE-2023-4604 Wordfence
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
8.8 High Depicter — Popup & Slider Builder Plugin depicter Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload ≤ 3.1.1 CVE-2024-4389 Wordfence
5.9 Medium Slider by Soliloquy Plugin soliloquy-lite Broken Access Control Broken Access Control to XSS ≤ 2.7.6 Fixed in 2.7.7 CVE-2024-35775 Patchstack
5.9 Medium Depicter Slider Plugin depicter Cross-Site Scripting ≤ 3.1.2 Fixed in 3.2.0 CVE-2024-43161 Patchstack
8.8 High Slider by 10Web – Responsive Image Slider Plugin slider-wd SQL Injection Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.2.57 CVE-2024-7150 Wordfence
5.9 Medium NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) ≤ 3.59.3 Fixed in 3.59.4 CVE-2024-39627 Patchstack
5.4 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Editor+ Stored XSS < 1.2.57 Fixed in 1.2.57 CVE-2024-6408 WPScan
6.5 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion No login needed ≤ 3.9.10 CVE-2024-6490 WPScan
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget ≤ 1.3.980 CVE-2024-5818 Wordfence
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title ≤ 3.2.19 CVE-2024-3896 Wordfence
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Gallery Slideshow Plugin gallery-slideshow Cross-Site Scripting ≤ 1.4.1 CVE-2024-37246 Patchstack
5.9 Medium Depicter Slider Plugin depicter Cross-Site Scripting ≤ 3.0.2 Fixed in 3.1.0 CVE-2024-37414 Patchstack
5.9 Medium Slider Revolution Plugin Cross-Site Scripting ≤ 6.7.13 Fixed in 6.7.14 CVE-2024-37449 Patchstack
7.1 High Simple Responsive Slider Plugin simple-responsive-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.2.5 CVE-2024-37954 Patchstack
6.5 Medium GutSlider – All in One Block Slider Plugin slider-blocks Cross-Site Scripting All in One Block Slider plugin <= 2.7.3 - Cross Site Scripting (XSS) ≤ 2.7.3 CVE-2024-37955 Patchstack
6.5 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Cross-Site Scripting ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-38686 Patchstack
6.5 Medium Advanced post slider Plugin advanced-post-slider Cross-Site Scripting ≤ 3.0.0 CVE-2024-38750 Patchstack
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Editor+ Stored XSS No login needed < 1.2.56 Fixed in 1.2.56 CVE-2024-6026 WPScan
6.4 Medium Webico Slider Flatsome Addons Plugin webico-slider-flatsome-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wbc_image Shortcode ≤ 2.0.1 CVE-2024-5881 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Marquee Text Widget, Testimonials Widget, and Testimonial Slider Widgets ≤ 8.4.1 CVE-2024-3638 Wordfence
6.4 Medium Ultimate Post Kit Addons for Elementor Plugin ultimate-post-kit Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget ≤ 3.11.7 CVE-2024-5662 Wordfence
6.1 Medium Simple AL Slider Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2.10 CVE-2024-5729 WPScan
6.5 Medium Slideshow SE Plugin slideshow-se Local File Inclusion Auth. Limited Local File Inclusion ≤ 2.5.17 Fixed in 2.5.18 CVE-2024-35778 Patchstack
6.5 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-35762 Patchstack
5.9 Medium Slideshow SE Plugin slideshow-se Cross-Site Scripting ≤ 2.5.17 CVE-2024-35769 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only