WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 672 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical VikAppointments Services Booking Calendar Plugin vikappointments Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter No login needed ≤ 1.2.21 CVE-2026-87115 Wordfence
3.7 Low Booking Calendar Plugin booking Other Race Condition No login needed ≤ 11.8.4 CVE-2026-39601 Patchstack
5.3 Medium Appointment Booking Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter No login needed ≤ 5.7.1 CVE-2026-94432 Wordfence
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter No login needed ≤ 1.8.28 CVE-2026-102565 Wordfence
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
5.4 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-62063 Patchstack
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
9.1 Critical Appointment Booking Plugin latepoint Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field No login needed ≤ 5.7.0 CVE-2026-92966 Wordfence
9.8 Critical Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.7.1 Fixed in 1.18.8 CVE-2026-97248 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.5.0 Fixed in 6.5.2 CVE-2026-97079 Patchstack
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
6.5 Medium Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object References (IDOR) ≤ 28.2 Fixed in 28.3 CVE-2026-96347 Patchstack
5.3 Medium Course Booking System Plugin course-booking-system Information Disclosure Unauthenticated Attendee PII Disclosure via CSV Export No login needed 7.0 – < 7.0.9 Fixed in 7.0.9 CVE-2026-96886 WPScan
5.3 Medium Bookly Plugin Price Manipulation Unauthenticated Payment Bypass via Booking Price Manipulation No login needed < 28.3 Fixed in 28.3 CVE-2026-86838 WPScan
9.1 Critical Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter No login needed ≤ 28.2 CVE-2026-93399 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data No login needed ≤ 28.2 CVE-2026-92799 Wordfence
7.5 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control No login needed ≤ 4.6.0 Fixed in 4.6.3 CVE-2026-95513 Patchstack
2.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Unpublished Event Disclosure via mpwem_load_event_list 5.3.6 – < 5.7.3 Fixed in 5.7.3 CVE-2026-91077 WPScan
4.3 Medium Booking Manager Plugin booking-manager Broken Access Control Subscriber+ Arbitrary User Plugin Meta Modification via IDOR < 2.1.21 Fixed in 2.1.21 CVE-2026-91025 WPScan
6.8 Medium Booking Manager Plugin booking-manager SQL Injection Author+ SQLi via ICS Import Feed UID (sync_gid) < 2.1.21 Fixed in 2.1.21 CVE-2026-91024 WPScan
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter No login needed ≤ 11.8.3 CVE-2026-93655 Wordfence
5.3 Medium Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Booking Data Tampering No login needed 1.3.4 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87840 WPScan
5.5 Medium Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Account Modification and Deletion via IDOR < 1.2.4 Fixed in 1.2.4 CVE-2026-92425 WPScan
4.7 Medium Hydra Booking 1.1.0 Plugin Broken Access Control < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 1.1.0 – < 1.2.3 Fixed in 1.2.3 CVE-2026-92421 WPScan
3.8 Low Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR < 1.2.2 Fixed in 1.2.2 CVE-2026-92420 WPScan
4.3 Medium LatePoint Plugin latepoint Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking) ≤ 5.6.3 CVE-2026-13471 Wordfence
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'options' Parameter No login needed ≤ 11.8.2 CVE-2026-92561 Wordfence
7.2 High Booking Calendar Plugin booking Privilege Escalation Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter ≤ 11.8.2 CVE-2026-92619 Wordfence
8.8 High iGMS Direct Booking Plugin igms-direct-booking Cross-Site Scripting Unauthenticated Stored XSS via Widget Settings No login needed < 2.0 Fixed in 2.0 CVE-2026-88825 WPScan
8.8 High VikBooking Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Chat Attachment No login needed 1.8.8 – < 1.8.15 Fixed in 1.8.15 CVE-2026-85127 WPScan
4.3 Medium LatePoint - Appointment Booking & Scheduling Plugin latepoint Broken Access Control Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter ≤ 5.6.9 CVE-2026-18441 Wordfence
5.3 Medium Booking for Appointments and Events Calendar - Amelia Plugin Broken Access Control Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass No login needed ≤ 2.4.5 CVE-2026-16582 Wordfence
5.4 Medium Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Broken Access Control Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover ≤ 2.4.4 CVE-2026-14311 Wordfence
5.3 Medium Booking Calendar Plugin booking Broken Access Control No login needed ≤ 11.7 Fixed in 11.8 CVE-2026-74002 Patchstack
9.8 Critical EduAdmin Booking Plugin eduadmin-booking Authentication Bypass Broken Authentication No login needed ≤ 5.4.2 Fixed in 6.0.0 CVE-2026-62101 Patchstack
4.9 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Payment Gateway Credential Disclosure 5.3.6 – < 5.6.0 Fixed in 5.6.0 CVE-2026-91019 WPScan
3.7 Low Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel No login needed 5.3.6 – < 5.3.8 Fixed in 5.3.8 CVE-2026-91008 WPScan
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Other Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission No login needed < 1.5.95 Fixed in 1.5.95 CVE-2026-86475 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Internal Notes Disclosure via Service and Category REST Routes No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87907 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Staff PII Disclosure via Agent REST Route No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87896 WPScan
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
9.8 Critical JetFormBuilder Plugin jetformbuilder Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed ≤ 3.6.2 CVE-2026-12793 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action No login needed ≤ 1.2.3 CVE-2026-14349 Wordfence
7.2 High MotoPress Hotel Booking Plugin motopress-hotel-booking-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' No login needed ≤ 6.2.4 CVE-2026-90650 Wordfence
7.5 High Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce Plugin wp-event-solution Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter ≤ 4.1.23 CVE-2026-75983 Wordfence
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter ≤ 2.4.9 CVE-2026-10148 Wordfence
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87892 WPScan
6.5 Medium Rox Appointment Booking Plugin rox-appointment-booking Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87891 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only