WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Appointment Booking Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter No login needed ≤ 5.7.1 CVE-2026-94432 Wordfence
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
5.4 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-62063 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.5.0 Fixed in 6.5.2 CVE-2026-97079 Patchstack
6.5 Medium Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object References (IDOR) ≤ 28.2 Fixed in 28.3 CVE-2026-96347 Patchstack
5.3 Medium Course Booking System Plugin course-booking-system Information Disclosure Unauthenticated Attendee PII Disclosure via CSV Export No login needed 7.0 – < 7.0.9 Fixed in 7.0.9 CVE-2026-96886 WPScan
5.3 Medium Bookly Plugin Price Manipulation Unauthenticated Payment Bypass via Booking Price Manipulation No login needed < 28.3 Fixed in 28.3 CVE-2026-86838 WPScan
5.3 Medium Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data No login needed ≤ 28.2 CVE-2026-92799 Wordfence
4.3 Medium Booking Manager Plugin booking-manager Broken Access Control Subscriber+ Arbitrary User Plugin Meta Modification via IDOR < 2.1.21 Fixed in 2.1.21 CVE-2026-91025 WPScan
6.8 Medium Booking Manager Plugin booking-manager SQL Injection Author+ SQLi via ICS Import Feed UID (sync_gid) < 2.1.21 Fixed in 2.1.21 CVE-2026-91024 WPScan
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter No login needed ≤ 11.8.3 CVE-2026-93655 Wordfence
5.3 Medium Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Booking Data Tampering No login needed 1.3.4 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87840 WPScan
5.5 Medium Hydra Booking Plugin Broken Access Control Hydra Host+ Cross-Host Account Modification and Deletion via IDOR < 1.2.4 Fixed in 1.2.4 CVE-2026-92425 WPScan
4.7 Medium Hydra Booking 1.1.0 Plugin Broken Access Control < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 1.1.0 – < 1.2.3 Fixed in 1.2.3 CVE-2026-92421 WPScan
4.3 Medium LatePoint Plugin latepoint Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking) ≤ 5.6.3 CVE-2026-13471 Wordfence
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'options' Parameter No login needed ≤ 11.8.2 CVE-2026-92561 Wordfence
4.3 Medium LatePoint - Appointment Booking & Scheduling Plugin latepoint Broken Access Control Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter ≤ 5.6.9 CVE-2026-18441 Wordfence
5.3 Medium Booking for Appointments and Events Calendar - Amelia Plugin Broken Access Control Amelia <= 2.4.5 - Missing Authorization to Unauthenticated Payment Bypass No login needed ≤ 2.4.5 CVE-2026-16582 Wordfence
5.4 Medium Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Broken Access Control Amelia (Premium) <= 2.4.4 - Authenticated (Custom+) Missing Authorization to Limited Account Takeover ≤ 2.4.4 CVE-2026-14311 Wordfence
5.3 Medium Booking Calendar Plugin booking Broken Access Control No login needed ≤ 11.7 Fixed in 11.8 CVE-2026-74002 Patchstack
4.9 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Information Disclosure Contributor+ Payment Gateway Credential Disclosure 5.3.6 – < 5.6.0 Fixed in 5.6.0 CVE-2026-91019 WPScan
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Other Unauthenticated Booking Capacity Bypass via Multi-Appointment Submission No login needed < 1.5.95 Fixed in 1.5.95 CVE-2026-86475 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Internal Notes Disclosure via Service and Category REST Routes No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87907 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Staff PII Disclosure via Agent REST Route No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87896 WPScan
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter ≤ 2.4.9 CVE-2026-10148 Wordfence
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Customer PII Disclosure via IDOR No login needed 1.0.9 – < 1.2.3 Fixed in 1.2.3 CVE-2026-87894 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Price Manipulation Unauthenticated Price Manipulation and Payment Method Restriction Bypass No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87892 WPScan
6.5 Medium Rox Appointment Booking Plugin rox-appointment-booking Broken Access Control Unauthenticated Holiday Schedule Modification via REST API No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-87891 WPScan
5.3 Medium Booktics – Booking Calendar for Appointments and Service Businesses Plugin booktics Broken Access Control Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization No login needed ≤ 1.0.23 CVE-2026-11446 Wordfence
6.5 Medium Salon booking system Plugin salon-booking-system Broken Access Control No login needed ≤ 10.31.8 CVE-2026-81793 Patchstack
4.3 Medium Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) Plugin wp-event-solution Broken Access Control Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption ≤ 4.1.22 CVE-2026-15398 Wordfence
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-18042 WPScan
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
5.4 Medium Events Manager - Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Scripting Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes No login needed ≤ 7.3.3 CVE-2025-14945 Wordfence
5.3 Medium E-cab Taxi Booking Manager for Woocommerce Plugin ecab-taxi-booking-manager Price Manipulation Unauthenticated Price Manipulation via mptbm_add_to_cart No login needed 2.0.1 – < 2.0.5 Fixed in 2.0.5 CVE-2026-84045 WPScan
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
5.3 Medium Appointment Booking Lite Plugin Broken Access Control Unauthenticated Arbitrary Reservation Deletion No login needed < 2.4.8 Fixed in 2.4.8 CVE-2026-15232 WPScan
6.5 Medium Amelia Plugin Broken Access Control Unauthenticated Post-Booking Action Trigger No login needed < 2.4.9 Fixed in 2.4.9 CVE-2026-14215 WPScan
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via Service and Option Cost Parameters No login needed < 1.7.25 Fixed in 1.7.25 CVE-2026-16986 WPScan
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78258 Patchstack
4.3 Medium WooCommerce Bookings Plugin Broken Access Control Subscriber+ Draft Bookable Product Creation via Missing Authorization < 3.9.0 Fixed in 3.9.0 CVE-2026-14853 WPScan
6.5 Medium WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting ≤ 6.3.2 Fixed in 6.4.0 CVE-2026-73402 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control < 2.0.8 Fixed in 2.0.8 CVE-2026-73363 Patchstack
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18779 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Information Disclosure Unauthenticated Customer PII Disclosure via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18778 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Arbitrary Appointment Status Change via update_appointment_status No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18777 WPScan
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.5.91 CVE-2026-66679 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only