WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 74 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103066 Patchstack
7.2 High JetAppointment Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter No login needed ≤ 2.5.2.1 CVE-2026-93875 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce No login needed ≤ 1.6.12.32 CVE-2026-92245 Wordfence
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Local File Inclusion Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter ≤ 1.6.12.27 CVE-2026-89294 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
7.1 High Easy Appointments Plugin easy-appointments Cross-Site Scripting No login needed ≤ 4.0.2.1 CVE-2026-81798 Patchstack
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
7.2 High Booking for Appointments and Events Calendar Plugin ameliabooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission No login needed ≤ 2.2 CVE-2026-6286 Wordfence
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65513 Patchstack
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint No login needed < 1.6.12.6 Fixed in 1.6.12.6 CVE-2026-16540 WPScan
7.5 High TrueBooker Plugin truebooker-appointment-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2.2 CVE-2026-13161 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool SQL Injection Unauthenticated SQL Injection No login needed ≤ 27.5 CVE-2026-14516 Wordfence
8.1 High Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion ≤ 3.12.27 CVE-2026-8789 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
7.5 High BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection Unauthenticated SQL Injection via 'store_service_date' Parameter No login needed ≤ 5.7.1 CVE-2026-11823 Wordfence
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.2 Fixed in 1.6.12.4 CVE-2026-57317 Patchstack
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Information Disclosure Sensitive Data Exposure No login needed ≤ 27.4 Fixed in 27.5 CVE-2026-42667 Patchstack
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Sensitive Data Exposure No login needed < 1.6.11.2 Fixed in 1.6.11.2 CVE-2026-42384 Patchstack
8.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-39587 Patchstack
7.5 High Easy Appointments Plugin easy-appointments Broken Access Control No login needed ≤ 3.12.21 Fixed in 3.12.22 CVE-2026-39513 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.10.6 Fixed in 1.6.11.0 CVE-2026-39447 Patchstack
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.11.8 CVE-2026-7797 Wordfence
7.5 High Easy Appointments Plugin easy-appointments Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 3.12.21 CVE-2026-2262 Wordfence
8.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39495 Patchstack
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters No login needed ≤ 1.6.9.9 CVE-2025-12166 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
7.5 High Booking Calendar | Appointment Booking | Bookit Plugin bookit Broken Access Control Missing Authorization to Unauthenticated Stripe Connection No login needed ≤ 2.5.0 CVE-2025-12633 Wordfence
7.1 High gAppointments Plugin gappointments Cross-Site Scripting No login needed ≤ 1.14.1 CVE-2025-49951 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
8.8 High QuickCal - Appointment Booking Calendar Plugin quickcal Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32310 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
7.6 High BMA Lite Plugin bma-lite-appointment-booking-and-scheduling SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-39518 Patchstack
7.6 High BookingPress Plugin bookingpress-appointment-booking SQL Injection ≤ 1.1.28 Fixed in 1.1.38 CVE-2025-31910 Patchstack
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
7.5 High Doctor Appointment Booking Plugin doctor-appointment-booking Local File Inclusion ≤ 1.0.0 CVE-2025-27264 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only