WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 207 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Hydra Booking Plugin hydra-booking Privilege Escalation No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68027 Patchstack
8.6 High Movie Booking Plugin movie-booking Arbitrary File Deletion No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-67963 Patchstack
8.1 High Booking Activities Plugin booking-activities Privilege Escalation No login needed ≤ 1.16.44 Fixed in 1.16.45 CVE-2025-67953 Patchstack
7.2 High Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) Plugin wp-event-solution Broken Access Control Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings' No login needed ≤ 4.0.51 CVE-2025-14657 Wordfence
7.5 High Booking Package Plugin booking-package Price Manipulation No login needed ≤ 1.6.27 Fixed in 1.6.29 CVE-2024-30516 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68055 Patchstack
7.5 High Booking Calendar Plugin booking SQL Injection Unauthenticated SQL Injection via dates_to_check No login needed ≤ 10.14.8 CVE-2025-14383 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
7.5 High Booking Calendar | Appointment Booking | Bookit Plugin bookit Broken Access Control Missing Authorization to Unauthenticated Stripe Connection No login needed ≤ 2.5.0 CVE-2025-12633 Wordfence
7.2 High Alex Reservations: Smart Restaurant Booking Plugin alex-reservations Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload ≤ 2.2.3 CVE-2025-12399 Wordfence
8.1 High Alloggio - Hotel Booking Theme alloggio Local File Inclusion Hotel Booking Theme theme <= 1.8 - Local File Inclusion No login needed ≤ 1.8 CVE-2025-64287 Patchstack
7.1 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-49904 Patchstack
8.8 High Service Finder Bookings Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Account Takeover < 6.1 Fixed in 6.1 CVE-2025-6574 Wordfence
8.8 High Service Finder Bookings Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via change_candidate_password ≤ 6.0 CVE-2025-5949 Wordfence
7.1 High HotelRunner Booking Widget Plugin hotelrunner Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-60168 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49378 Patchstack
7.1 High WooCommerce Booking Bundle Hours Plugin woo-booking-bundle-hours Cross-Site Request Forgery No login needed ≤ 0.7.4 Fixed in 0.7.5 CVE-2025-58991 Patchstack
7.2 High Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin Plugin wp-event-solution Server-Side Request Forgery Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery No login needed ≤ 4.0.37 CVE-2025-7813 Wordfence
8.1 High Uxper Booking Plugin uxper-booking Local File Inclusion No login needed ≤ 1.3.3 CVE-2025-49892 Patchstack
8.5 High Uxper Booking Plugin uxper-booking SQL Injection ≤ 1.3.3 CVE-2025-49891 Patchstack
7.5 High Event Manager, Event Calendar and Booking Plugin eventin-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52731 Patchstack
7.3 High TheBooking Plugin thebooking Broken Access Control No login needed ≤ 1.4.4 CVE-2025-52801 Patchstack
8.8 High Hydra Booking Plugin hydra-booking Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function 1.1.0 – 1.1.18 CVE-2025-7689 Wordfence
7.1 High Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2025-52787 Patchstack
7.5 High Booking X Plugin booking-x Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via export_now() Function No login needed 1.0 – 1.1.2 CVE-2025-6814 Wordfence
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.7 Fixed in 3.8 CVE-2025-53259 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49323 Patchstack
8.5 High FAT Services Booking Plugin fat-services-booking SQL Injection ≤ 5.6 CVE-2025-39355 Patchstack
8.8 High QuickCal - Appointment Booking Calendar Plugin quickcal Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32310 Patchstack
7.5 High FAT Services Booking Plugin fat-services-booking Local File Inclusion ≤ 5.5 CVE-2025-47693 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.6 Fixed in 3.7 CVE-2025-47498 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.1.20 CVE-2025-27345 Patchstack
7.1 High Course Booking System Plugin course-booking-system Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-32508 Patchstack
8.8 High TuriTop Booking System Plugin turitop-booking-system PHP Object Injection ≤ 1.0.10 CVE-2025-32571 Patchstack
8.1 High Hotel Booking Plugin nd-booking Local File Inclusion No login needed ≤ 3.6 Fixed in 3.7 CVE-2025-39526 Patchstack
7.6 High BMA Lite Plugin bma-lite-appointment-booking-and-scheduling SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-39518 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-27011 Patchstack
7.5 High Beds24 Online Booking Plugin beds24-online-booking Local File Inclusion ≤ 2.0.28 Fixed in 2.0.29 CVE-2025-32155 Patchstack
7.1 High Awesome Event Booking Plugin awesome-event-booking Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.4 Fixed in 2.8.5 CVE-2025-31416 Patchstack
7.2 High Salon booking system Plugin salon-booking-system Privilege Escalation ≤ 10.15 Fixed in 10.15 CVE-2025-31560 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager PHP Object Injection ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30892 Patchstack
7.6 High BookingPress Plugin bookingpress-appointment-booking SQL Injection ≤ 1.1.28 Fixed in 1.1.38 CVE-2025-31910 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager Local File Inclusion ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30891 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
8.8 High Eventer - WordPress Event & Booking Manager Plugin SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id ≤ 3.9.9.2 CVE-2025-0959 Wordfence
7.5 High Doctor Appointment Booking Plugin doctor-appointment-booking Local File Inclusion ≤ 1.0.0 CVE-2025-27264 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only