WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 253 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed |
≤ 1.1.27 |
CVE-2025-12788 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed |
≤ 1.1.27 |
CVE-2025-12787 |
Wordfence | |
| 4.3 Medium | Private Google Calendars | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 20250811 |
CVE-2025-12526 |
Wordfence | |
| 4.3 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation |
≤ 4.2.0.0 |
CVE-2025-12498 |
Wordfence | |
| 5.3 Medium | The Events Calendar | Information Disclosure Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure No login needed |
≤ 6.15.9 |
CVE-2025-12192 |
Wordfence | |
| 4.3 Medium | The Events Calendar | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure |
≤ 6.15.9 |
CVE-2025-12175 |
Wordfence | |
| 6.5 Medium | Pie Calendar | Cross-Site Scripting |
≤ 1.2.9 Fixed in 1.3.0 |
CVE-2025-62024 |
Patchstack | |
| 6.4 Medium | Event Tickets, RSVPs, Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-9875 |
Wordfence | |
| 5.3 Medium | The Events Calendar | Broken Access Control Missing Authorization to Unauthenticated Password-Protected Information Disclosure No login needed |
≤ 6.15.2 |
CVE-2025-9808 |
Wordfence | |
| 6.4 Medium | Digital Events Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via column Parameter |
≤ 1.0.8 |
CVE-2025-5801 |
Wordfence | |
| 6.5 Medium | WP Simple Booking Calendar | Broken Access Control |
≤ 2.0.13 Fixed in 2.0.14 |
CVE-2025-39541 |
Patchstack | |
| 6.5 Medium | WordPress Events Calendar Plugin – connectDaily | Cross-Site Scripting connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) |
≤ 1.5.5 |
CVE-2025-58862 |
Patchstack | |
| 6.5 Medium | Pie Calendar | Cross-Site Scripting |
≤ 1.2.8 Fixed in 1.2.9 |
CVE-2025-58618 |
Patchstack | |
| 6.4 Medium | Booking Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.14.1 |
CVE-2025-9346 |
Wordfence | |
| 6.4 Medium | Intl DateTime Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via date Parameter |
≤ 1.0.1 |
CVE-2025-8293 |
Wordfence | |
| 6.5 Medium | Online Booking & Scheduling Calendar for WordPress by vcita | Cross-Site Scripting |
≤ 4.5.3 Fixed in 4.5.5 |
CVE-2025-54676 |
Patchstack | |
| 6.5 Medium | Event Manager, Event Calendar and Booking | Cross-Site Scripting |
≤ 4.0.24 Fixed in 4.0.25 |
CVE-2025-52730 |
Patchstack | |
| 5.9 Medium | Modern Events Calendar Lite | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.3.0 |
CVE-2021-4458 |
Wordfence | |
| 6.1 Medium | Event Manager | Cross-Site Scripting Reflected Cross-Site Scripting via `calendar_header` Parameter No login needed |
≤ 6.6.4.4, 7.0.1 – 7.0.3 |
CVE-2025-6975 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Popular Elementor Templates and Widgets | Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets |
≤ 6.1.19 |
CVE-2025-6244 |
Wordfence | |
| 6.5 Medium | Booking Calendar Contact Form | Cross-Site Scripting |
≤ 1.2.58 Fixed in 1.2.59 |
CVE-2025-48231 |
Patchstack | |
| 4.3 Medium | VR Calendar | Cross-Site Request Forgery Cross-Site Request Forgery to Calendar Sync No login needed |
≤ 2.4.7 |
CVE-2025-5936 |
Wordfence | |
| 6.4 Medium | IRM Newsroom | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'irmcalendarview' Shortcode |
≤ 1.2.19 |
CVE-2025-4586 |
Wordfence | |
| 6.4 Medium | The Events Calendar | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 6.13.2 |
CVE-2025-5144 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget |
≤ 6.1.12 |
CVE-2024-9993 |
Wordfence | |
| 5.9 Medium | Next Event Calendar | Cross-Site Scripting |
≤ 1.2 |
CVE-2023-26001 |
Patchstack | |
| 4.3 Medium | Quick Event Calendar | Cross-Site Request Forgery No login needed |
≤ 1.4.9 |
CVE-2025-27360 |
Patchstack | |
| 6.5 Medium | The Holiday Calendar | Cross-Site Scripting |
≤ 1.18.2.1 |
CVE-2025-29003 |
Patchstack | |
| 6.5 Medium | The Events Calendar Countdown Addon | Cross-Site Scripting |
≤ 1.4.9 Fixed in 1.4.10 |
CVE-2025-49311 |
Patchstack | |
| 5.3 Medium | Modern Events Calendar | Information Disclosure Information Exposure No login needed |
≤ 7.21.9 |
CVE-2025-5733 |
Wordfence | |
| 4.3 Medium | Bellevue | Broken Access Control |
≤ 4.2.2 |
CVE-2025-39398 |
Patchstack | |
| 5.4 Medium | The Events Calendar | Broken Access Control |
≤ 6.11.2.1 Fixed in 6.12.0 |
CVE-2025-48246 |
Patchstack | |
| 6.4 Medium | Booking Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode |
≤ 10.11.1 |
CVE-2025-4669 |
Wordfence | |
| 6.4 Medium | EventON - WordPress Virtual Event Calendar | Broken Access Control WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 4.9.6 |
CVE-2025-3527 |
Wordfence | |
| 4.3 Medium | QuickCal - Appointment Booking Calendar | Information Disclosure Sensitive Data Exposure |
≤ 1.0.15 Fixed in 1.0.16 |
CVE-2025-32299 |
Patchstack | |
| 6.4 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update |
3.4.9 – < 3.5.0 Fixed in 3.5.0 |
CVE-2024-4665 |
WPScan | |
| 4.8 Medium | Event Calendar | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.0.4 |
CVE-2024-8701 |
WPScan | |
| 4.8 Medium | The Events Calendar | Cross-Site Scripting Admin+ Stored XSS |
< 6.6.4 Fixed in 6.6.4 |
CVE-2024-8493 |
WPScan | |
| 4.3 Medium | Simple calendar for Elementor | Cross-Site Request Forgery No login needed |
≤ 1.6.5 Fixed in 1.6.6 |
CVE-2025-47542 |
Patchstack | |
| 4.3 Medium | Simple calendar for Elementor | Cross-Site Request Forgery No login needed |
≤ 1.6.4 Fixed in 1.6.5 |
CVE-2025-46249 |
Patchstack | |
| 5.3 Medium | Appointment Booking Calendar | Broken Access Control No login needed |
≤ 1.3.92 Fixed in 1.3.93 |
CVE-2025-46247 |
Patchstack | |
| 4.3 Medium | Online Booking & Scheduling Calendar for WordPress by vcita | Information Disclosure Sensitive Data Exposure |
≤ 4.5.5 Fixed in 4.6.0 |
CVE-2025-32238 |
Patchstack | |
| 6.5 Medium | Tockify Events Calendar | Cross-Site Scripting |
≤ 2.2.13 Fixed in 2.3.0 |
CVE-2025-32174 |
Patchstack | |
| 6.5 Medium | Booking Calendar and Notification | Authentication Bypass Broken Authentication No login needed |
≤ 4.0.3 |
CVE-2025-31381 |
Patchstack | |
| 6.5 Medium | Ethiopian Calendar | Cross-Site Scripting |
≤ 1.1.1 |
CVE-2025-31589 |
Patchstack | |
| 4.3 Medium | Multi Days Events and Multi Events in One Day Calendar | Cross-Site Request Forgery No login needed |
≤ 1.1.3 |
CVE-2025-31572 |
Patchstack | |
| 5.3 Medium | Booking for Appointments and Events Calendar – Amelia | Information Disclosure Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure No login needed |
≤ 1.2.19 |
CVE-2025-2578 |
Wordfence | |
| 6.5 Medium | Simple Google Calendar Outlook Events Block Widget | Cross-Site Scripting |
≤ 2.5.0 Fixed in 2.6.0 |
CVE-2025-22497 |
Patchstack | |
| 6.1 Medium | Registrations for The Events Calendar | Cross-Site Scripting Admin+ Stored XSS No login needed |
< 2.13.4 Fixed in 2.13.4 |
CVE-2024-10703 |
WPScan | |
| 5.3 Medium | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Broken Access Control Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update No login needed |
≤ 4.0.24 |
CVE-2025-1766 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.