WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1–50 of 133 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103066 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints No login needed ≤ 4.8.3 CVE-2026-97337 Wordfence
7.2 High JetAppointment Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter No login needed ≤ 2.5.2.1 CVE-2026-93875 Wordfence
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint ≤ 2.0.0 CVE-2026-95687 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce No login needed ≤ 1.6.12.32 CVE-2026-92245 Wordfence
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control No login needed ≤ 28.2 Fixed in 28.3 CVE-2026-96348 Patchstack
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Local File Inclusion Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter ≤ 1.6.12.27 CVE-2026-89294 Wordfence
7.1 High Realtyna Organic IDX plugin + WPL Real Estate Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting Reflected XSS via Location Selector Endpoint No login needed < 5.4.2 Fixed in 5.4.2 CVE-2026-91014 WPScan
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
8.8 High BE REST Endpoints Plugin Cross-Site Scripting Unauthenticated Stored XSS and Widget Manipulation No login needed ≤ 1.0.0 CVE-2026-81742 WPScan
8.1 High Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Authentication Bypass Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint No login needed ≤ 3.9.8 CVE-2026-76009 Wordfence
7.5 High Csomagpontok és szállítási címkék WooCommerce-hez Plugin hungarian-pickup-points-for-woocommerce Broken Access Control No login needed < 4.2.8 Fixed in 4.2.8 CVE-2026-81790 Patchstack
7.1 High Easy Appointments Plugin easy-appointments Cross-Site Scripting No login needed ≤ 4.0.2.1 CVE-2026-81798 Patchstack
8.2 High Auto x LINE Plugin Broken Access Control Unauthenticated REST API Endpoints Call No login needed ≤ 1.0.0 CVE-2025-15485 WPScan
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
7.2 High WP Rocket Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint No login needed ≤ 3.21.0.1 CVE-2026-5934 Wordfence
7.2 High Booking for Appointments and Events Calendar Plugin ameliabooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission No login needed ≤ 2.2 CVE-2026-6286 Wordfence
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
7.5 High WPAdverts Plugin wpadverts Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint No login needed ≤ 2.3.2 CVE-2026-11801 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
7.2 High Infility Global Plugin infility-global Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint No login needed ≤ 2.15.21 CVE-2026-10734 Wordfence
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
8.8 High KiviCare Plugin kivicare-clinic-management-system SQL Injection Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint < 4.5.2 Fixed in 4.5.2 CVE-2026-13613 WPScan
8.2 High Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Account Creation via Waiting List Endpoint No login needed < 4.1.20 Fixed in 4.1.20 CVE-2026-13171 WPScan
7.5 High GeoDirectory Plugin geodirectory Information Disclosure Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint No login needed < 2.8.169 Fixed in 2.8.169 CVE-2026-16988 WPScan
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65513 Patchstack
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13154 WPScan
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13153 WPScan
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16602 WPScan
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint No login needed < 1.6.12.6 Fixed in 1.6.12.6 CVE-2026-16540 WPScan
8.8 High FleekDash V2 Plugin fleekdash Broken Access Control Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint ≤ 2.6.2.2 CVE-2026-14356 Wordfence
7.5 High Uncanny Automator Plugin uncanny-automator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints No login needed ≤ 7.3.2 CVE-2026-15025 Wordfence
8.8 High Eazy Plugin Manager Plugin plugins-on-steroids Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint ≤ 4.4.1 CVE-2026-14328 Wordfence
7.5 High TrueBooker Plugin truebooker-appointment-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2.2 CVE-2026-13161 Wordfence
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool SQL Injection Unauthenticated SQL Injection No login needed ≤ 27.5 CVE-2026-14516 Wordfence
8.1 High Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion ≤ 3.12.27 CVE-2026-8789 Wordfence
8.0 High WPify Woo Plugin wpify-woo Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint ≤ 5.4.16 CVE-2026-12736 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
7.2 High SUMO Reward Points for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter No login needed ≤ 32.7.0 CVE-2026-7534 Wordfence
7.2 High MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint ≤ 8.14.0 CVE-2026-1771 Wordfence
7.5 High LearnPress Plugin learnpress Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints No login needed ≤ 4.4.1 CVE-2026-13765 Wordfence
8.8 High Divi Torque Lite Plugin addons-for-divi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint No login needed ≤ 4.2.3 CVE-2026-4275 Wordfence
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter ≤ 5.6.3 CVE-2026-13228 Wordfence
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint ≤ 5.0.4 CVE-2026-12224 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only