WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 110 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-39587 Patchstack
7.5 High Easy Appointments Plugin easy-appointments Broken Access Control No login needed ≤ 3.12.21 Fixed in 3.12.22 CVE-2026-39513 Patchstack
9.3 Critical Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection No login needed ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39493 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.10.6 Fixed in 1.6.11.0 CVE-2026-39447 Patchstack
5.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint No login needed ≤ 1.6.11.8 CVE-2026-6937 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.11.8 CVE-2026-7797 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Denial of Service Unauthenticated Denial of Service No login needed ≤ 1.6.11.5 CVE-2026-7493 Wordfence
6.5 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Unauthenticated Arbitrary Appointment View, Modification and Deletion No login needed ≤ 1.6.10.6 CVE-2026-4807 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint No login needed ≤ 2.1.2 CVE-2026-6449 Wordfence
7.5 High Easy Appointments Plugin easy-appointments Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 3.12.21 CVE-2026-2262 Wordfence
5.3 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.10.2 CVE-2026-39694 Patchstack
8.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39495 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
4.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure ≤ 1.6.9.29 CVE-2026-1704 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence
5.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure No login needed ≤ 5.2.6 CVE-2026-1537 Wordfence
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.9.15 Fixed in 1.6.9.17 CVE-2025-69315 Patchstack
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters No login needed ≤ 1.6.9.9 CVE-2025-12166 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.5 CVE-2025-11723 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
4.3 Medium Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution Plugin fluent-booking Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management ≤ 1.9.11 CVE-2025-13756 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
6.5 Medium Easy Appointments Plugin easy-appointments Content Injection No login needed ≤ 3.12.14 Fixed in 3.12.14.1 CVE-2025-49398 Patchstack
7.1 High gAppointments Plugin gappointments Cross-Site Scripting No login needed ≤ 1.14.1 CVE-2025-49951 Patchstack
9.8 Critical Appointments Plugin appointments PHP Object Injection Unauthenticated PHP Object Injection No login needed < 2.2.2 Fixed in 2.2.2 CVE-2017-20206 Wordfence
6.4 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 1.6.8.30 CVE-2025-4667 Wordfence
4.3 Medium Easy!Appointments Plugin easyappointments Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-31828 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2.19 CVE-2025-2578 Wordfence
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
6.1 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.3 CVE-2024-13431 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected XSS No login needed < 5.0.0 Fixed in 5.0.0 CVE-2024-12737 WPScan
8.8 High GetBookingsWp - Appointments & Bookings Plugin Basic Version Plugin get-bookings-wp Privilege Escalation Appointments & Bookings Plugin Basic Version <= 1.1.27 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 1.1.27 CVE-2024-13677 Wordfence
7.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting No login needed ≤ 5.0.0 Fixed in 5.1.0 CVE-2025-22684 Patchstack
7.1 High VikAppointments Services Booking Calendar Plugin vikappointments Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-22719 Patchstack
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control ≤ 1.1.12 Fixed in 1.1.13 CVE-2023-32601 Patchstack
4.3 Medium Easy Appointments Plugin easy-appointments Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) No login needed ≤ 3.10.7 Fixed in 3.11.1 CVE-2023-30748 Patchstack
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
6.4 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7.14 CVE-2024-4288 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only