WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 551–600 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.2.15 CVE-2024-9504 Wordfence
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
6.4 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via beds24-link Shortcode ≤ 2.0.27 CVE-2024-10177 Wordfence
6.5 Medium Multi-day Booking Calendar Plugin multi-day-booking-calendar Cross-Site Scripting ≤ 1.0.1 CVE-2024-51873 Patchstack
6.5 Medium Minical Hotel Booking Plugin minical Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-51895 Patchstack
6.5 Medium EzyOnlineBookings Online Booking System Widget Plugin ezyonlinebookings-online-booking-system Cross-Site Scripting ≤ 1.3 CVE-2024-51628 Patchstack
5.9 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.25 Fixed in 2.0.26 CVE-2024-51664 Patchstack
8.5 High Lodgix.com Vacation Rental Website Builder Plugin lodgixcom-vacation-rental-listing-management-booking-plugin SQL Injection ≤ 3.9.73 CVE-2024-50539 Patchstack
4.8 Medium WP Booking Calendar Plugin Cross-Site Scripting Admin+ Stored XSS < 10.6.3 Fixed in 10.6.3 CVE-2024-10027 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
7.5 High WP Hotel Booking Plugin wp-hotel-booking Local File Inclusion ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-51582 Patchstack
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
7.5 High WpTravelly Plugin tour-booking-manager Broken Access Control No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-43212 Patchstack
6.5 Medium WP Booking System Plugin wp-booking-system Broken Access Control Booking Calendar plugin <= 2.0.19.10 - Broken Access Control ≤ 2.0.19.10 Fixed in 2.0.19.11 CVE-2024-50425 Patchstack
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.4.7 CVE-2024-9864 Wordfence
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed ≤ 4.0.4.7 CVE-2024-9865 Wordfence
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
6.5 Medium Booking.com Banner Creator Plugin bookingcom-banner-creator Cross-Site Scripting ≤ 1.4.6 CVE-2024-49265 Patchstack
5.9 Medium Multipurpose Ticket Booking Manager Plugin bus-booking-manager Cross-Site Scripting ≤ 4.2.2 Fixed in 4.2.3 CVE-2024-44037 Patchstack
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.6 Fixed in 4.5 CVE-2024-47638 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 10.9 Fixed in 10.9.1 CVE-2024-47316 Patchstack
4.4 Medium WP Booking Calendar Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 10.6 CVE-2024-9306 Wordfence
8.8 High WP Hotel Booking Plugin wp-hotel-booking Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.1.2 CVE-2024-7855 Wordfence
8.8 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation ≤ 6.7.12 CVE-2024-8290 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
5.9 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Cross-Site Scripting ≤ 5.3.5 Fixed in 5.3.6 CVE-2024-43985 Patchstack
6.1 Medium WP Booking System – Booking Calendar Plugin wp-booking-system Cross-Site Scripting Booking Calendar <= 2.0.19.8 - Reflected Cross-Site Scripting No login needed ≤ 2.0.19.8 CVE-2024-8797 Wordfence
6.1 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.10 CVE-2024-8663 Wordfence
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection Multiple Unauthenticated SQLi No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6924 WPScan
8.8 High Pinpoint Booking System Plugin booking-system SQL Injection Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection ≤ 2.9.9.5.0 CVE-2024-7112 Wordfence
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
6.1 Medium WP Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 10.5 CVE-2024-8274 Wordfence
7.6 High Salon booking system Plugin salon-booking-system SQL Injection Authenticated SQL Injection ≤ 10.7 Fixed in 10.8 CVE-2024-39658 Patchstack
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack
6.1 Medium OTA Sync Booking Engine Widget Plugin ota-sync-booking-engine-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2024-7647 Wordfence
4.7 Medium Salon booking system Plugin salon-booking-system Open Redirect No login needed ≤ 10.8.1 Fixed in 10.9 CVE-2024-43280 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
9.8 Critical Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking Authentication Bypass BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover No login needed 1.1.6 – 1.1.7 CVE-2024-7350 Wordfence
5.4 Medium Pinpoint Booking System Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.9.9.4.8 Fixed in 2.9.9.4.8 CVE-2024-3636 WPScan
6.4 Medium WP Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingform Shortcode ≤ 10.2.1 CVE-2024-6930 Wordfence
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37262 Patchstack
6.5 Medium WP Travel Engine Plugin wp-travel-engine Cross-Site Scripting Tour Booking Plugin – Tour Operator Software plugin <= 5.9.1 - Cross Site Scripting (XSS) ≤ 5.9.1 Fixed in 5.9.2 CVE-2024-37944 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates ≤ 1.1.13 CVE-2024-6175 Wordfence
8.8 High BookingPress Appointment Booking Plugin bookingpress-appointment-booking Path Traversal Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation ≤ 1.1.5 CVE-2024-6467 Wordfence
8.8 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Broken Access Control Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload ≤ 1.1.5 CVE-2024-6660 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only