WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 253 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
6.4 Medium Hammas Calendar Plugin hammas-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Shortcode Attribute ≤ 1.5.11 CVE-2026-1902 Wordfence
6.4 Medium My Calendar – Accessible Event Manager Plugin my-calendar Cross-Site Scripting Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.7.3 CVE-2026-2355 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API ≤ 6.15.16 CVE-2026-2694 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.8.3 Fixed in 4.2.8.4 CVE-2026-25389 Patchstack
4.4 Medium Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters ≤ 1.2.7 CVE-2026-1044 Wordfence
6.4 Medium XO Event Calendar Plugin xo-event-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_event_field' shortcode ≤ 3.2.10 CVE-2026-0556 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification ≤ 10.14.14 CVE-2026-2230 Wordfence
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter ≤ 4.2.8.4 CVE-2026-1655 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint No login needed ≤ 4.2.8.4 CVE-2026-1657 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence
5.3 Medium Appointment Booking Calendar Plugin bookr Broken Access Control Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification No login needed ≤ 1.0.2 CVE-2026-1932 Wordfence
5.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure No login needed ≤ 5.2.6 CVE-2026-1537 Wordfence
6.4 Medium The Events Calendar Shortcode & Block Plugin the-events-calendar-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.1.2 CVE-2026-1922 Wordfence
6.5 Medium The Events Calendar Shortcode & Block Plugin the-events-calendar-shortcode Cross-Site Scripting ≤ 3.1.1 Fixed in 3.1.2 CVE-2026-24988 Patchstack
5.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed ≤ 10.14.13 CVE-2026-1431 Wordfence
5.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion No login needed ≤ 1.6.6 CVE-2026-1310 Wordfence
4.4 Medium Appointment Hour Booking – Booking Calendar Plugin appointment-hour-booking Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration ≤ 1.5.60 CVE-2026-1083 Wordfence
4.3 Medium Sugar Calendar (Lite) Plugin sugar-calendar-lite Broken Access Control ≤ 3.9.1 Fixed in 3.10.0 CVE-2026-24636 Patchstack
5.3 Medium WP FullCalendar Plugin wp-fullcalendar Information Disclosure Sensitive Data Exposure No login needed ≤ 1.6 CVE-2026-24523 Patchstack
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.2.8.0 Fixed in 4.2.8.1 CVE-2026-24380 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Migration Control ≤ 6.15.13 CVE-2025-15043 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 10.14.11 CVE-2025-14982 Wordfence
5.3 Medium EventPrime - Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Information Disclosure Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.0 CVE-2025-14507 Wordfence
5.3 Medium Booking Calendar Plugin booking Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 10.14.10 CVE-2025-14146 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.15.12.2 Fixed in 6.15.13 CVE-2025-69352 Patchstack
4.3 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2025-69348 Patchstack
6.5 Medium Appointment Booking and Scheduling Calendar Plugin – WP Timetics Plugin timetics Broken Access Control WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification No login needed ≤ 1.0.36 CVE-2025-5919 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.5 CVE-2025-11723 Wordfence
6.5 Medium Kalender.digital Plugin kalender-digital Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-62752 Patchstack
5.3 Medium Google Calendar Events Plugin google-calendar-events Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2025-68979 Patchstack
5.4 Medium Editorial Calendar Plugin editorial-calendar Broken Access Control ≤ 3.8.8 Fixed in 3.8.9 CVE-2025-68603 Patchstack
4.3 Medium Spiffy Calendar Plugin spiffy-calendar Broken Access Control ≤ 5.0.7 Fixed in 5.0.8 CVE-2025-68523 Patchstack
6.4 Medium Calendar Plugin calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'event_desc' ≤ 1.3.16 CVE-2025-14548 Wordfence
5.3 Medium Pretty Google Calendar Plugin pretty-google-calendar Broken Access Control Missing Authorization to Unauthenticated Google API Key Exposure No login needed ≤ 2.0.0 CVE-2025-12898 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
4.3 Medium Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed ≤ 7.2.2.2 CVE-2025-12407 Wordfence
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Information Disclosure Sensitive Data Exposure ≤ 4.2.4.1 Fixed in 4.2.5.0 CVE-2025-63007 Patchstack
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control ≤ 4.2.4.1 Fixed in 4.2.5.0 CVE-2025-63006 Patchstack
4.3 Medium My Calendar Plugin my-calendar Broken Access Control ≤ 3.6.16 Fixed in 3.6.17 CVE-2025-67592 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-67574 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67559 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode ≤ 10.14.6 CVE-2025-12804 Wordfence
4.3 Medium Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution Plugin fluent-booking Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management ≤ 1.9.11 CVE-2025-13756 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter No login needed ≤ 1.2.60 CVE-2025-13318 Wordfence
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter No login needed ≤ 1.3.96 CVE-2025-13317 Wordfence
6.5 Medium Booking Calendar Plugin booking Cross-Site Scripting ≤ 10.14.7 Fixed in 10.14.8 CVE-2025-64381 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only