WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 112 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WPBase Cache Plugin wpbase-cache Denial of Service Denial of Service Attack ≤ 5.5.6 CVE-2026-39767 Patchstack
9.3 Critical Radius Booking — Booking Calendar for Appointments & Services Plugin radius-booking SQL Injection No login needed ≤ 1.0.19 CVE-2026-39764 Patchstack
8.5 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103066 Patchstack
9.3 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events SQL Injection No login needed ≤ 6.4.0 Fixed in 6.5.0 CVE-2026-103352 Patchstack
9.1 Critical VikAppointments Services Booking Calendar Plugin vikappointments Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter No login needed ≤ 1.2.21 CVE-2026-87115 Wordfence
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter No login needed ≤ 1.8.28 CVE-2026-102565 Wordfence
5.3 Medium Two Factor Plugin two-factor Denial of Service Denial of Service Attack No login needed ≤ 0.16.0 Fixed in 0.17.0 CVE-2026-100508 Patchstack
5.9 Medium WP Store Locator Plugin wp-store-locator Denial of Service Denial of Service Attack No login needed < 3.0.0 Fixed in 3.0.0 CVE-2026-94681 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title ≤ 5.7.2 CVE-2026-88037 Wordfence
8.2 High Divi Dash Plugin Denial of Service Unauthenticated Denial of Service via IP Address Spoofing No login needed < 1.0.7 Fixed in 1.0.7 CVE-2026-14321 WPScan
5.3 Medium Rox Appointment Booking Plugin rox-appointment-booking Information Disclosure Unauthenticated Internal Notes Disclosure via Service and Category REST Routes No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-87907 WPScan
5.3 Medium Booktics – Booking Calendar for Appointments and Service Businesses Plugin booktics Broken Access Control Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization No login needed ≤ 1.0.23 CVE-2026-11446 Wordfence
6.4 Medium Builderall Plugin builderall-cheetah-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting ≤ 3.0.2 CVE-2026-15796 Wordfence
7.5 High WooCommerce Plugin woocommerce Denial of Service Denial of Service Attack No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-48888 Patchstack
5.4 Medium Search Atlas SEO Plugin metasync Broken Access Control Subscriber+ Google Service Account Credential Overwrite/Deletion < 2.6.24 Fixed in 2.6.24 CVE-2026-15247 WPScan
7.5 High Migrate Guru – Site Migration & Cloning Plugin migrate-guru Denial of Service Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack No login needed ≤ 6.65 Fixed in 6.72 CVE-2026-84778 Patchstack
7.5 High MalCare Security Plugin malcare-security Denial of Service Denial of Service Attack No login needed ≤ 6.69 Fixed in 6.72 CVE-2026-84776 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
5.3 Medium WP Go Maps Plugin wp-google-maps Denial of Service Denial of Service Attack No login needed ≤ 10.1.08 Fixed in 10.1.09 CVE-2026-84780 Patchstack
5.3 Medium Really Simple SSL Plugin really-simple-ssl Denial of Service Denial of Service Attack No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84775 Patchstack
7.5 High Smush Image Compression and Optimization Plugin wp-smushit Denial of Service Denial of Service Attack No login needed ≤ 4.2.0 Fixed in 4.3.0 CVE-2026-81285 Patchstack
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via Service and Option Cost Parameters No login needed < 1.7.25 Fixed in 1.7.25 CVE-2026-16986 WPScan
6.5 Medium WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting ≤ 6.3.2 Fixed in 6.4.0 CVE-2026-73402 Patchstack
7.5 High Starter Templates by Kadence WP Plugin kadence-starter-templates Denial of Service Denial of Service Attack No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-73997 Patchstack
6.5 Medium WpBookingly Plugin service-booking-manager Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-66687 Patchstack
10.0 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2026-61962 Patchstack
8.8 High Service Finder Booking Plugin sf-booking Privilege Escalation ≤ 6.2 CVE-2026-28161 Patchstack
6.5 Medium Service Finder Booking Plugin sf-booking Broken Access Control ≤ 6.2 CVE-2026-28159 Patchstack
7.5 High WP Maps Pro Plugin Denial of Service Unauthenticated Denial of Service No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-18464 WPScan
6.5 Medium WP Maps Plugin wp-google-map-plugin Denial of Service Subscriber+ Denial of Service < 4.9.7 Fixed in 4.9.7 CVE-2026-16265 WPScan
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
9.1 Critical Masteriyo LMS Plugin learning-management-system Denial of Service Unauthenticated Arbitrary User Session Termination (Denial of Service) No login needed < 2.3.1 Fixed in 2.3.1 CVE-2026-13332 WPScan
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
5.3 Medium LatePoint Plugin latepoint Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter No login needed ≤ 5.6.2 CVE-2026-12657 Wordfence
7.5 High BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection Unauthenticated SQL Injection via 'store_service_date' Parameter No login needed ≤ 5.7.1 CVE-2026-11823 Wordfence
6.4 Medium Appointment Booking Calendar Plugin creavi-booking-service Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label ≤ 1.4.4 CVE-2026-1856 Wordfence
6.4 Medium Services Section Block Plugin services-section Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute ≤ 1.4.4 CVE-2026-11402 Wordfence
7.4 High Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons Plugin chatway-live-chat Information Disclosure AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin <= 1.4.8 - Sensitive Data Exposure ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-49082 Patchstack
8.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-39587 Patchstack
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Denial of Service Unauthenticated Denial of Service No login needed ≤ 1.6.11.5 CVE-2026-7493 Wordfence
4.3 Medium WpBookingly Plugin service-booking-manager Broken Access Control ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-25444 Patchstack
6.5 Medium WpBookingly Plugin service-booking-manager Broken Access Control ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-27405 Patchstack
7.5 High WPGraphQL Plugin wp-graphql Denial of Service WordPress Plugin WPGraphQL 1.3.5 Denial of Service No login needed 1.3.5 CVE-2021-47959 VulnCheck
7.5 High WpBookingly Plugin service-booking-manager Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32384 Patchstack
8.1 High AC Services | HVAC, Air Conditioning & Heating Company Theme window-ac-services Local File Inclusion No login needed ≤ 1.2.5 CVE-2026-27326 Patchstack
9.8 Critical Handyman Theme handyman-services PHP Object Injection No login needed ≤ 1.4.7 CVE-2026-22451 Patchstack
4.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection ≤ 12.4.14 CVE-2025-14342 Wordfence
5.3 Medium CallbackKiller service widget Plugin callbackkiller-service-widget Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update No login needed ≤ 1.2 CVE-2026-1944 Wordfence
5.4 Medium Electrician - Electrical Service Plugin electrician Server-Side Request Forgery Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) No login needed ≤ 5.6 CVE-2026-22358 Patchstack
5.4 Medium Pool Services Theme pool-services Server-Side Request Forgery No login needed ≤ 3.3 CVE-2025-62741 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only