WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–82 of 82 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Yoga Schedule Momoyoga Plugin momoyoga-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 CVE-2025-9852 Wordfence
5.3 Medium CoSchedule Plugin coschedule-by-todaymade Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.11 Fixed in 3.4.0 CVE-2025-60119 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54676 Patchstack
6.4 Medium Conference Scheduler Plugin conference-scheduler Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter ≤ 2.5.1 CVE-2025-5258 Wordfence
6.4 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 1.6.8.30 CVE-2025-4667 Wordfence
5.4 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Cross-Site Scripting Contributor+ Stored XSS < 8.4.0 Fixed in 8.4.0 CVE-2025-4133 WPScan
6.5 Medium Contact Form Builder by vcita Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.10.2 Fixed in 4.10.5 CVE-2025-32199 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Information Disclosure Sensitive Data Exposure ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-32238 Patchstack
6.5 Medium Appointy Appointment Scheduler Plugin appointy-appointment-scheduler Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 4.2.1 CVE-2025-31601 Patchstack
4.7 Medium Scheduled & Automatic Order Status Controller for WooCommerce Plugin order-status-rules-for-woocommerce Open Redirect No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30781 Patchstack
6.1 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.3 CVE-2024-13431 Wordfence
5.3 Medium Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Plugin evergreen-content-poster Broken Access Control Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 1.4.4 CVE-2024-12071 Wordfence
4.9 Medium Database Backup and check Tables Automated With Scheduler 2024 Plugin database-backup Path Traversal Authenticated (Admin+) Arbitrary File Read ≤ 2.32 CVE-2024-12850 Wordfence
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5 Fixed in 4.5.2 CVE-2024-54356 Patchstack
5.3 Medium Rate My Post – Star Rating Plugin by FeedbackWP Plugin rate-my-post Broken Access Control Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled Posts No login needed ≤ 4.2.4 CVE-2024-12309 Wordfence
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.5.1 CVE-2024-9872 Wordfence
6.4 Medium Contact Form Builder Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via livesite-pay Shortcode ≤ 4.10.4 CVE-2024-10056 Wordfence
4.3 Medium PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes Plugin revisionary Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 3.5.15 CVE-2024-11154 Wordfence
6.1 Medium PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes Plugin revisionary Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.14 CVE-2024-9436 Wordfence
6.1 Medium Store Hours for WooCommerce Plugin order-hours-scheduler-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.3.20 CVE-2024-8872 Wordfence
5.5 Medium Timetable and Event Schedule Plugin mp-timetable PHP Object Injection ≤ 2.4.13 CVE-2024-39630 Patchstack
6.4 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via File Upload ≤ 7.5.4 CVE-2024-7302 Wordfence
5.3 Medium SchedulePress Plugin wp-scheduled-posts Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 5.1.3 CVE-2024-6557 Wordfence
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Local File Inclusion ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37499 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-35761 Patchstack
6.4 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7.14 CVE-2024-4288 Wordfence
5.4 Medium WPCal.io – Easy Meeting Scheduler Plugin wpcal Cross-Site Request Forgery No login needed ≤ 0.9.5.8 Fixed in 0.9.5.9 CVE-2024-34816 Patchstack
6.5 Medium SchedulePress Plugin wp-scheduled-posts Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2024-32717 Patchstack
5.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Information Disclosure Information Exposure No login needed ≤ 7.4.2 CVE-2024-3678 Wordfence
4.3 Medium WPCal.io – Easy Meeting Scheduler Plugin wpcal Cross-Site Request Forgery No login needed ≤ 0.9.5.8 Fixed in 0.9.5.9 CVE-2024-32795 Patchstack
6.5 Medium Yoga Schedule Momoyoga Plugin momoyoga-integration Cross-Site Scripting ≤ 2.7.0 CVE-2024-32529 Patchstack
4.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Reset No login needed ≤ 1.6.6.20 CVE-2024-1760 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only