WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 207 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.4 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2026-57723 Patchstack
7.5 High BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection Unauthenticated SQL Injection via 'store_service_date' Parameter No login needed ≤ 5.7.1 CVE-2026-11823 Wordfence
8.8 High Eagle Booking Plugin eagle-booking Cross-Site Request Forgery No login needed ≤ 1.3.4.3 CVE-2025-68052 Patchstack
8.8 High Entrepreneur - Booking for Small Businesses Theme entrepreneurx PHP Object Injection Booking for Small Businesses WordPress Theme theme < 3.1.5 - PHP Object Injection < 3.1.5 Fixed in 3.1.5 CVE-2025-69130 Patchstack
7.3 High Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.30.24 Fixed in 10.30.25 CVE-2026-40768 Patchstack
8.5 High Directorist Booking Plugin directorist-booking SQL Injection ≤ 3.0.3 Fixed in 3.0.4 CVE-2026-49073 Patchstack
8.1 High Alloggio - Hotel Booking Theme alloggio PHP Object Injection Hotel Booking theme <= 2.1.2 - PHP Object Injection No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-39539 Patchstack
8.8 High Amelia Plugin ameliabooking Privilege Escalation ≤ 2.3 Fixed in 2.4 CVE-2026-48889 Patchstack
8.5 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form SQL Injection ≤ 1.2.50 Fixed in 1.2.51 CVE-2026-48882 Patchstack
7.5 High Bookly Plugin bookly-responsive-appointment-booking-tool Information Disclosure Sensitive Data Exposure No login needed ≤ 27.4 Fixed in 27.5 CVE-2026-42667 Patchstack
7.5 High Salon booking system Plugin salon-booking-system Broken Access Control No login needed ≤ 10.30.25 Fixed in 10.30.26 CVE-2026-42666 Patchstack
7.1 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Scripting No login needed ≤ 1.2.46 Fixed in 1.2.47 CVE-2026-40791 Patchstack
7.5 High Amelia Plugin ameliabooking Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2 Fixed in 2.2.1 CVE-2026-40789 Patchstack
7.5 High Booking Package Plugin booking-package Broken Access Control No login needed ≤ 1.7.06 Fixed in 1.7.07 CVE-2026-40774 Patchstack
8.1 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-39587 Patchstack
7.5 High WpTravelly Plugin tour-booking-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-27089 Patchstack
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
7.2 High Booking Package Plugin booking-package Privilege Escalation Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action ≤ 1.7.16 CVE-2026-9851 Wordfence
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.1.41 Fixed in 1.1.42 CVE-2026-42675 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.8 Fixed in 1.8.9 CVE-2026-42683 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.11.8 CVE-2026-7797 Wordfence
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2026-42762 Patchstack
8.6 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Arbitrary File Deletion No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2026-42737 Patchstack
7.2 High Booking Calendar – Event Calendar Plugin Cross-Site Scripting Event Calendar <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.1.6 CVE-2026-8143 Wordfence
7.5 High Court Reservation – Manage Your Court Bookings Online Plugin court-reservation SQL Injection Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injection No login needed ≤ 1.10.11 CVE-2026-1250 Wordfence
7.5 High Gravity Bookings Plugin SQL Injection Unauthenticated SQL Injection via 'category_id' Parameter No login needed ≤ 2.5.9 CVE-2026-1719 Wordfence
7.2 High LatePoint Plugin latepoint Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter No login needed ≤ 5.5.0 CVE-2026-7332 Wordfence
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
7.5 High Salon Booking System – Free Version Plugin salon-booking-system Path Traversal Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path Traversal No login needed ≤ 10.30.25 CVE-2026-6320 Wordfence
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-39487 Patchstack
8.8 High Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter ≤ 2.1.3 CVE-2026-5465 Wordfence
7.2 High Fluent Booking Plugin fluent-booking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.0.01 CVE-2026-2231 Wordfence
8.8 High Amelia Booking Plugin ameliabooking Broken Access Control Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change ≤ 9.1.2 CVE-2026-2931 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
8.1 High Salon Booking System Pro Plugin salon-booking-plugin-pro Privilege Escalation Account Takeover No login needed ≤ 10.30.12 Fixed in 10.30.12 CVE-2026-25334 Patchstack
7.2 High Vagaro Booking Widget Plugin vagaro-booking-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' No login needed ≤ 0.3 CVE-2026-3003 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
7.5 High WpBookingly Plugin service-booking-manager Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32384 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 10.14.15 Fixed in 10.14.16 CVE-2026-32358 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
7.5 High JetBooking Plugin SQL Injection Unauthenticated SQL Injection via 'check_in_date' Parameter No login needed ≤ 4.0.3 CVE-2026-3496 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
8.5 High Eagle Booking Plugin eagle-booking SQL Injection ≤ 1.3.4.3 CVE-2026-27428 Patchstack
8.8 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2026-27390 Patchstack
7.5 High DesignThemes Booking Manager Plugin designthemes-booking-manager Broken Access Control No login needed ≤ 2.0 CVE-2026-27388 Patchstack
7.2 High Amelia Plugin ameliabooking Privilege Escalation ≤ 1.2.38 Fixed in 2.0 CVE-2026-24963 Patchstack
7.5 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69340 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only