WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 206 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter No login needed ≤ 1.8.28 CVE-2026-102565 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
7.5 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control No login needed ≤ 4.6.0 Fixed in 4.6.3 CVE-2026-95513 Patchstack
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
7.2 High Booking Calendar Plugin booking Privilege Escalation Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter ≤ 11.8.2 CVE-2026-92619 Wordfence
8.8 High iGMS Direct Booking Plugin igms-direct-booking Cross-Site Scripting Unauthenticated Stored XSS via Widget Settings No login needed < 2.0 Fixed in 2.0 CVE-2026-88825 WPScan
8.8 High VikBooking Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Chat Attachment No login needed 1.8.8 – < 1.8.15 Fixed in 1.8.15 CVE-2026-85127 WPScan
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
7.2 High MotoPress Hotel Booking Plugin motopress-hotel-booking-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' No login needed ≤ 6.2.4 CVE-2026-90650 Wordfence
7.5 High Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce Plugin wp-event-solution Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter ≤ 4.1.23 CVE-2026-75983 Wordfence
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-62112 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.1 CVE-2026-81769 Patchstack
7.5 High BookingPress Plugin Price Manipulation Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation No login needed 1.5.6 – < 1.6.3 Fixed in 1.6.3 CVE-2026-76586 WPScan
7.2 High Booking for Appointments and Events Calendar Plugin ameliabooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission No login needed ≤ 2.2 CVE-2026-6286 Wordfence
8.1 High FluentBooking Pro Plugin fluent-booking-pro Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-81273 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
8.5 High Gravity Forms Bookings premium Plugin gf-bookings-premium SQL Injection ≤ 2.1 CVE-2026-32466 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter No login needed ≤ 6.8.4 CVE-2026-17087 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-28188 Patchstack
8.8 High Booking Activities Plugin booking-activities PHP Object Injection No login needed ≤ 1.18.4 Fixed in 1.18.5 CVE-2026-28176 Patchstack
8.8 High Service Finder Booking Plugin sf-booking Privilege Escalation ≤ 6.2 CVE-2026-28161 Patchstack
7.5 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.5 CVE-2026-27345 Patchstack
8.1 High Events Manager Plugin events-manager SQL Injection Subscriber+ Booking Consent Record Tampering via SQL Injection < 7.4.1 Fixed in 7.4.1 CVE-2026-18057 WPScan
7.5 High Salon Booking System – Free Version Plugin Information Disclosure Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard No login needed < 10.30.34 Fixed in 10.30.34 CVE-2026-17022 WPScan
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Booking Manager+ Missing Authorization via rtb_reset_notifications No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15151 WPScan
7.5 High TrueBooker Plugin truebooker-appointment-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2.2 CVE-2026-13161 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool SQL Injection Unauthenticated SQL Injection No login needed ≤ 27.5 CVE-2026-14516 Wordfence
7.1 High Booking Calendar Plugin booking Cross-Site Scripting No login needed ≤ 11.4.2 Fixed in 11.4.3 CVE-2026-59558 Patchstack
7.5 High Byteflows Travel & Hotel Booking Plugin byteflows-travel-hotel-booking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.0 Fixed in 1.0.1 CVE-2026-59548 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Price Manipulation No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2026-59532 Patchstack
8.2 High BookingPress Pro Plugin Information Disclosure Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug No login needed < 5.7.3 Fixed in 5.7.3 CVE-2026-9830 WPScan
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter No login needed ≤ 1.8.13 CVE-2026-15401 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
7.1 High WP Booking System Plugin wp-booking-system-premium Broken Access Control < 5.12.8.1 Fixed in 5.12.8.1 CVE-2026-57367 Patchstack
7.5 High Events Manager Plugin events-manager SQL Injection Unauthenticated SQL Injection via PHP Object Injection in Booking Registration No login needed < 7.3.7 Fixed in 7.3.7 CVE-2026-12987 WPScan
7.1 High Hydra Booking Plugin hydra-booking Cross-Site Scripting No login needed ≤ 1.1.44 Fixed in 1.1.45 CVE-2026-57388 Patchstack
7.5 High Booking Package Plugin booking-package SQL Injection Unauthenticated SQL Injection via 'email' Form Parameter No login needed ≤ 1.7.20 CVE-2026-15335 Wordfence
8.8 High Salon Booking System Plugin salon-booking-system Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter No login needed ≤ 10.30.32 CVE-2026-15070 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field No login needed ≤ 1.8.8 CVE-2026-6820 Wordfence
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter No login needed ≤ 1.8.8 CVE-2026-6818 Wordfence
8.1 High BookingPress Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.1.28 CVE-2026-12378 WPScan
7.4 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2026-57723 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only