WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–97 of 97 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Path Traversal Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read No login needed ≤ 4.0.26 CVE-2025-3419 Wordfence
7.1 High Availability Calendar Plugin availability Cross-Site Request Forgery No login needed ≤ 0.2.4 CVE-2025-46528 Patchstack
7.1 High Contact Form 7 Calendar Plugin cf7-calendar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.1 CVE-2025-46510 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
7.1 High WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Request Forgery connectDaily plugin <= 1.5.4 - CSRF to Cross-Site Scripting No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-32597 Patchstack
7.1 High CGM Event Calendar Plugin cgm-event-calendar Cross-Site Scripting No login needed ≤ 0.8.5 CVE-2025-31462 Patchstack
7.6 High bizcalendar-web Plugin bizcalendar-web SQL Injection ≤ 1.1.0.34 Fixed in 1.1.0.35 CVE-2025-30843 Patchstack
8.5 High WP Google Calendar Manager Plugin wp-gcalendar SQL Injection ≤ 2.1 CVE-2025-28939 Patchstack
7.1 High Another Events Calendar Plugin another-events-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.0 CVE-2025-26536 Patchstack
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.24 CVE-2025-1770 Wordfence
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory PHP Object Injection ≤ 2.3.14 Fixed in 2.3.15 CVE-2025-26967 Patchstack
7.1 High Swift Calendar Online Appointment Scheduling Plugin online-appointment-scheduling-software Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23526 Patchstack
7.5 High Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager SQL Injection Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter No login needed ≤ 6.6.3 CVE-2024-11260 Wordfence
7.1 High VikAppointments Services Booking Calendar Plugin vikappointments Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-22719 Patchstack
7.2 High EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Cross-Site Scripting Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name No login needed ≤ 4.0.7.3 CVE-2024-12024 Wordfence
7.2 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.2.15 CVE-2024-9504 Wordfence
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.6 Fixed in 4.5 CVE-2024-47638 Patchstack
7.5 High VR Calendar Plugin vr-calendar-sync Local File Inclusion No login needed ≤ 2.4.0 Fixed in 2.4.5 CVE-2024-44013 Patchstack
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.8 CVE-2024-7149 Wordfence
7.2 High The Events Calendar Plugin the-events-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 6.6.3 CVE-2024-6931 Wordfence
7.6 High Spiffy Calendar Plugin spiffy-calendar SQL Injection ≤ 4.9.12 Fixed in 4.9.13 CVE-2024-43969 Patchstack
7.1 High Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45458 Patchstack
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
8.5 High Registrations for the Events Calendar Plugin registrations-for-the-events-calendar SQL Injection ≤ 2.12.2 Fixed in 2.12.3 CVE-2024-39638 Patchstack
8.5 High Modern Events Calendar Plugin modern-events-calendar-lite Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery ≤ 7.12.1 CVE-2024-6522 Wordfence
7.6 High Spiffy Calendar Plugin spiffy-calendar SQL Injection ≤ 4.9.11 Fixed in 4.9.12 CVE-2024-38692 Patchstack
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37262 Patchstack
8.8 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Broken Access Control Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload ≤ 1.1.5 CVE-2024-6660 Wordfence
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
8.8 High Modern Events Calendar Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.11.0 CVE-2024-5441 Wordfence
7.3 High Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin timetics Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 1.0.21 CVE-2024-1094 Wordfence
8.2 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Booking Price Manipulation No login needed ≤ 3.3.4 Fixed in 3.3.5 CVE-2024-31275 Patchstack
8.2 High ICS Calendar Plugin ics-calendar Server-Side Request Forgery SSRF and Arbitrary File Read No login needed ≤ 10.12.0.3 Fixed in 10.12.0.4 CVE-2023-46784 Patchstack
7.5 High MF Gig Calendar Plugin Cross-Site Request Forgery Arbitrary Event Deletion via CSRF No login needed ≤ 1.2.1 CVE-2024-3756 WPScan
8.8 High Calendar Plugin calendar SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.3.14 CVE-2024-2831 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.6.7.7 CVE-2024-2341 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.6.7.7 CVE-2024-2342 Wordfence
7.2 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Arbitrary File Upload Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.87 CVE-2024-3022 Wordfence
7.1 High Appointment Calendar Plugin appointment-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.6 CVE-2024-30561 Patchstack
8.5 High Calendarista Plugin SQL Injection ≤ 15.5.7 Fixed in 15.5.9 CVE-2024-30240 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 9.4.3 Fixed in 9.4.3.1 CVE-2023-23991 Patchstack
8.2 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 3.3.9 Fixed in 3.4.0 CVE-2024-24832 Patchstack
7.1 High Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-27993 Patchstack
8.8 High Booking Calendar Plugin booking Cross-Site Request Forgery CSRF appointment scheduling No login needed < 1.3.83 Fixed in 1.3.83 CVE-2024-0856 WPScan
7.4 High Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar ≤ 5.9.9 CVE-2024-1536 Wordfence
7.6 High Events Shortcodes For The Events Calendar Plugin template-events-calendar SQL Injection WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-52142 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only