WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 58 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical VikAppointments Services Booking Calendar Plugin vikappointments Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter No login needed ≤ 1.2.21 CVE-2026-87115 Wordfence
9.1 Critical Appointment Booking Plugin latepoint Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field No login needed ≤ 5.7.0 CVE-2026-92966 Wordfence
9.8 Critical Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.7.1 Fixed in 1.18.8 CVE-2026-97248 Patchstack
9.1 Critical Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter No login needed ≤ 28.2 CVE-2026-93399 Wordfence
9.8 Critical EduAdmin Booking Plugin eduadmin-booking Authentication Bypass Broken Authentication No login needed ≤ 5.4.2 Fixed in 6.0.0 CVE-2026-62101 Patchstack
9.8 Critical JetFormBuilder Plugin jetformbuilder Privilege Escalation Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter No login needed ≤ 3.6.2 CVE-2026-12793 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action No login needed ≤ 1.2.3 CVE-2026-14349 Wordfence
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
9.8 Critical Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Privilege Escalation Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' No login needed 8.0 – 9.6.2 CVE-2026-9055 Wordfence
9.3 Critical BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection No login needed ≤ 6.0.2 CVE-2026-68566 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-18315 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-73347 Patchstack
9.8 Critical TrueBooker Appointment Booking Plugin Privilege Escalation Unauthenticated Account Takeover via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18776 WPScan
9.3 Critical JetAppointment Plugin jet-appointments-booking SQL Injection No login needed ≤ 2.5.2 Fixed in 2.5.2.1 CVE-2026-73365 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-16142 Wordfence
9.8 Critical Salon booking system Plugin salon-booking-system Authentication Bypass Broken Authentication No login needed ≤ 10.30.26 Fixed in 10.30.27 CVE-2026-66453 Patchstack
10.0 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2026-61962 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' No login needed ≤ 1.2.3 CVE-2026-14364 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' No login needed ≤ 1.2.3 CVE-2026-14365 Wordfence
9.8 Critical TrueBooker Appointment Booking Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset No login needed < 1.2.4 Fixed in 1.2.4 CVE-2026-14545 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-61951 Patchstack
9.3 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-61950 Patchstack
9.3 Critical Bookly Plugin bookly-responsive-appointment-booking-tool SQL Injection No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61949 Patchstack
9.3 Critical Amelia Plugin ameliabooking SQL Injection No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-57702 Patchstack
9.9 Critical Travel Booking Theme travel-booking Arbitrary File Upload ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-56059 Patchstack
9.3 Critical JetBooking Plugin jet-booking SQL Injection No login needed ≤ 4.0.4.1 Fixed in 4.0.4.2 CVE-2026-54820 Patchstack
9.1 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.9 Fixed in 1.2.0 CVE-2026-48881 Patchstack
9.8 Critical BookingPress Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Signature Custom Field No login needed ≤ 5.6 CVE-2026-6960 Wordfence
9.3 Critical Directorist Booking Plugin directorist-booking SQL Injection No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-22336 Patchstack
9.8 Critical Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation PHP Object Injection No login needed ≤ 5.6.0 CVE-2026-27095 Patchstack
9.8 Critical WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2026-27389 Patchstack
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
9.8 Critical WP Travel Engine – Tour Booking Plugin – Tour Operator Software Plugin wp-travel-engine Local File Inclusion Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion No login needed ≤ 6.6.7 CVE-2025-7634 Wordfence
9.8 Critical WP Travel Engine – Tour Booking Plugin – Tour Operator Software Plugin wp-travel-engine Arbitrary File Deletion Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming No login needed ≤ 6.6.7 CVE-2025-7526 Wordfence
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via claim_business No login needed ≤ 6.0 CVE-2025-5948 Wordfence
9.1 Critical WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Subscriber+ Rating Manipulation No login needed < 2.2.3 Fixed in 2.2.3 CVE-2025-8942 WPScan
9.1 Critical Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Arbitrary File Upload ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54677 Patchstack
9.8 Critical Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-54713 Patchstack
9.8 Critical Taxi Booking Manager for Woocommerce | E-cab Plugin ecab-taxi-booking-manager Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 1.3.0 CVE-2025-8898 Wordfence
9.8 Critical Service Finder Bookings Plugin Authentication Bypass Authentication Bypass via User Switch Cookie No login needed ≤ 6.0 CVE-2025-5947 Wordfence
9.8 Critical Service Finder Booking Plugin sf-booking Privilege Escalation No login needed ≤ 6.1 CVE-2025-23970 Patchstack
9.3 Critical Bus Ticket Booking with Seat Reservation for WooCommerce Plugin scw-bus-seat-reservation SQL Injection No login needed ≤ 1.7 CVE-2025-31397 Patchstack
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' No login needed ≤ 5.1 CVE-2025-2470 Wordfence
9.8 Critical WpBookingly Plugin service-booking-manager PHP Object Injection No login needed ≤ 1.3.0 CVE-2025-32607 Patchstack
9.3 Critical Booking Calendar and Notification Plugin booking-calendar-and-notification SQL Injection No login needed ≤ 4.0.3 CVE-2025-31403 Patchstack
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 5.0 CVE-2024-13442 Wordfence
9.3 Critical Course Booking System Plugin course-booking-system SQL Injection No login needed ≤ 6.0.6 Fixed in 6.0.7 CVE-2025-22785 Patchstack
9.3 Critical FAT Services Booking Plugin fat-services-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.6 CVE-2024-54221 Patchstack
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection Multiple Unauthenticated SQLi No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6924 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only