WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 51–100 of 672 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.4.9 Fixed in 2.4.10 CVE-2026-62112 Patchstack
5.3 Medium Booktics – Booking Calendar for Appointments and Service Businesses Plugin booktics Broken Access Control Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization No login needed ≤ 1.0.23 CVE-2026-11446 Wordfence
6.5 Medium Salon booking system Plugin salon-booking-system Broken Access Control No login needed ≤ 10.31.8 CVE-2026-81793 Patchstack
4.3 Medium Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) Plugin wp-event-solution Broken Access Control Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption ≤ 4.1.22 CVE-2026-15398 Wordfence
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-18042 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Booking Payment State Tampering via IDOR No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13146 WPScan
3.7 Low WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Payment Reset No login needed < 12.0.2 Fixed in 12.0.2 CVE-2026-13144 WPScan
5.4 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update ≤ 27.2 CVE-2026-2520 Wordfence
5.4 Medium Events Manager - Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Scripting Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes No login needed ≤ 7.3.3 CVE-2025-14945 Wordfence
5.3 Medium E-cab Taxi Booking Manager for Woocommerce Plugin ecab-taxi-booking-manager Price Manipulation Unauthenticated Price Manipulation via mptbm_add_to_cart No login needed 2.0.1 – < 2.0.5 Fixed in 2.0.5 CVE-2026-84045 WPScan
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.1 CVE-2026-81769 Patchstack
5.3 Medium Appointment Booking Lite Plugin Broken Access Control Unauthenticated Arbitrary Reservation Deletion No login needed < 2.4.8 Fixed in 2.4.8 CVE-2026-15232 WPScan
6.5 Medium Amelia Plugin Broken Access Control Unauthenticated Post-Booking Action Trigger No login needed < 2.4.9 Fixed in 2.4.9 CVE-2026-14215 WPScan
9.8 Critical Booking for Appointments and Events Calendar – Amelia (Premium) Plugin Privilege Escalation Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' No login needed 8.0 – 9.6.2 CVE-2026-9055 Wordfence
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
7.5 High BookingPress Plugin Price Manipulation Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation No login needed 1.5.6 – < 1.6.3 Fixed in 1.6.3 CVE-2026-76586 WPScan
7.2 High Booking for Appointments and Events Calendar Plugin ameliabooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission No login needed ≤ 2.2 CVE-2026-6286 Wordfence
8.1 High FluentBooking Pro Plugin fluent-booking-pro Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-81273 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via Service and Option Cost Parameters No login needed < 1.7.25 Fixed in 1.7.25 CVE-2026-16986 WPScan
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78258 Patchstack
4.3 Medium WooCommerce Bookings Plugin Broken Access Control Subscriber+ Draft Bookable Product Creation via Missing Authorization < 3.9.0 Fixed in 3.9.0 CVE-2026-14853 WPScan
6.5 Medium WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting ≤ 6.3.2 Fixed in 6.4.0 CVE-2026-73402 Patchstack
9.3 Critical BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection No login needed ≤ 6.0.2 CVE-2026-68566 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-18315 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control < 2.0.8 Fixed in 2.0.8 CVE-2026-73363 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-73347 Patchstack
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18779 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Information Disclosure Unauthenticated Customer PII Disclosure via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18778 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Arbitrary Appointment Status Change via update_appointment_status No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18777 WPScan
9.8 Critical TrueBooker Appointment Booking Plugin Privilege Escalation Unauthenticated Account Takeover via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18776 WPScan
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
9.3 Critical JetAppointment Plugin jet-appointments-booking SQL Injection No login needed ≤ 2.5.2 Fixed in 2.5.2.1 CVE-2026-73365 Patchstack
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.5.91 CVE-2026-66679 Patchstack
8.5 High Gravity Forms Bookings premium Plugin gf-bookings-premium SQL Injection ≤ 2.1 CVE-2026-32466 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter No login needed ≤ 6.8.4 CVE-2026-17087 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure ≤ 1.6.12.10 CVE-2026-13358 Wordfence
4.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter ≤ 27.7 CVE-2026-12905 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-16142 Wordfence
6.4 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter ≤ 1.2.2 CVE-2026-15948 Wordfence
5.3 Medium Pinpoint Booking System Plugin booking-system Price Manipulation Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter No login needed ≤ 2.9.9.6.8 CVE-2026-12128 Wordfence
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action No login needed ≤ 3.2.36 CVE-2026-8840 Wordfence
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
4.3 Medium Astro Booking Engine Plugin astro-booking-engine Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 1.4.0 CVE-2025-10308 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only