WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 253 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed ≤ 1.1.27 CVE-2025-12788 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed ≤ 1.1.27 CVE-2025-12787 Wordfence
4.3 Medium Private Google Calendars Plugin private-google-calendars Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 20250811 CVE-2025-12526 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Broken Access Control Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation ≤ 4.2.0.0 CVE-2025-12498 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure No login needed ≤ 6.15.9 CVE-2025-12192 Wordfence
4.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure ≤ 6.15.9 CVE-2025-12175 Wordfence
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2025-62024 Patchstack
6.4 Medium Event Tickets, RSVPs, Calendar Plugin ticket-spot Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-9875 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Unauthenticated Password-Protected Information Disclosure No login needed ≤ 6.15.2 CVE-2025-9808 Wordfence
6.4 Medium Digital Events Calendar Plugin digital-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via column Parameter ≤ 1.0.8 CVE-2025-5801 Wordfence
6.5 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Broken Access Control ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-39541 Patchstack
6.5 Medium WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Scripting connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 CVE-2025-58862 Patchstack
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-58618 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.14.1 CVE-2025-9346 Wordfence
6.4 Medium Intl DateTime Calendar Plugin intl-datetime-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via date Parameter ≤ 1.0.1 CVE-2025-8293 Wordfence
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54676 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
5.9 Medium Modern Events Calendar Lite Plugin modern-events-calendar-lite SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.3.0 CVE-2021-4458 Wordfence
6.1 Medium Event Manager Plugin events-manager Cross-Site Scripting Reflected Cross-Site Scripting via `calendar_header` Parameter No login needed ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6975 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets ≤ 6.1.19 CVE-2025-6244 Wordfence
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
4.3 Medium VR Calendar Plugin vr-calendar-sync Cross-Site Request Forgery Cross-Site Request Forgery to Calendar Sync No login needed ≤ 2.4.7 CVE-2025-5936 Wordfence
6.4 Medium IRM Newsroom Plugin irm-newsroom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'irmcalendarview' Shortcode ≤ 1.2.19 CVE-2025-4586 Wordfence
6.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.13.2 CVE-2025-5144 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
5.9 Medium Next Event Calendar Plugin next-event-calendar Cross-Site Scripting ≤ 1.2 CVE-2023-26001 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
6.5 Medium The Holiday Calendar Plugin the-holiday-calendar Cross-Site Scripting ≤ 1.18.2.1 CVE-2025-29003 Patchstack
6.5 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Cross-Site Scripting ≤ 1.4.9 Fixed in 1.4.10 CVE-2025-49311 Patchstack
5.3 Medium Modern Events Calendar Plugin modern-events-calendar-lite Information Disclosure Information Exposure No login needed ≤ 7.21.9 CVE-2025-5733 Wordfence
4.3 Medium Bellevue Theme bellevuex Broken Access Control ≤ 4.2.2 CVE-2025-39398 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.11.2.1 Fixed in 6.12.0 CVE-2025-48246 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode ≤ 10.11.1 CVE-2025-4669 Wordfence
6.4 Medium EventON - WordPress Virtual Event Calendar Plugin Broken Access Control WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.9.6 CVE-2025-3527 Wordfence
4.3 Medium QuickCal - Appointment Booking Calendar Plugin quickcal Information Disclosure Sensitive Data Exposure ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32299 Patchstack
6.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update 3.4.9 – < 3.5.0 Fixed in 3.5.0 CVE-2024-4665 WPScan
4.8 Medium Event Calendar Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.4 CVE-2024-8701 WPScan
4.8 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Admin+ Stored XSS < 6.6.4 Fixed in 6.6.4 CVE-2024-8493 WPScan
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-47542 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2025-46249 Patchstack
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46247 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Information Disclosure Sensitive Data Exposure ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-32238 Patchstack
6.5 Medium Tockify Events Calendar Plugin tockify-events-calendar Cross-Site Scripting ≤ 2.2.13 Fixed in 2.3.0 CVE-2025-32174 Patchstack
6.5 Medium Booking Calendar and Notification Plugin booking-calendar-and-notification Authentication Bypass Broken Authentication No login needed ≤ 4.0.3 CVE-2025-31381 Patchstack
6.5 Medium Ethiopian Calendar Plugin ethiopian-calendar Cross-Site Scripting ≤ 1.1.1 CVE-2025-31589 Patchstack
4.3 Medium Multi Days Events and Multi Events in One Day Calendar Plugin dragon-calendar-free-version Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31572 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2.19 CVE-2025-2578 Wordfence
6.5 Medium Simple Google Calendar Outlook Events Block Widget Plugin simple-google-icalendar-widget Cross-Site Scripting ≤ 2.5.0 Fixed in 2.6.0 CVE-2025-22497 Patchstack
6.1 Medium Registrations for The Events Calendar Plugin registrations-for-the-events-calendar Cross-Site Scripting Admin+ Stored XSS No login needed < 2.13.4 Fixed in 2.13.4 CVE-2024-10703 WPScan
5.3 Medium Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update No login needed ≤ 4.0.24 CVE-2025-1766 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only