WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 402 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Booking calendar, Appointment Booking System Plugin booking-calendar SQL Injection Unauthenticated Time-Based SQL Injection via 'wpdevart_id' No login needed ≤ 3.2.17 CVE-2026-15289 Wordfence
6.1 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters No login needed ≤ 2.3.1 CVE-2026-11392 Wordfence
4.3 Medium Hydra Booking Plugin hydra-booking Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter ≤ 1.2.1 CVE-2026-12433 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step No login needed ≤ 5.6.1 CVE-2026-11398 Wordfence
5.3 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite Broken Access Control Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter No login needed ≤ 2.4.4 CVE-2026-9180 Wordfence
6.5 Medium Hotel Booking Lite Plugin motopress-hotel-booking-lite Information Disclosure Sensitive Data Exposure ≤ 6.0.3 Fixed in 6.0.4 CVE-2026-57347 Patchstack
5.3 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Broken Access Control Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter No login needed ≤ 2.7.6 CVE-2026-9188 Wordfence
5.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 6.4.13 Fixed in 6.4.14 CVE-2026-27409 Patchstack
6.1 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross-Site Scripting via 'layoutstyle' Parameter No login needed ≤ 1.8.12 CVE-2026-12754 Wordfence
6.5 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite SQL Injection Authenticated (Staff+) SQL Injection via 's' Parameter ≤ 2.4.5 CVE-2026-13454 Wordfence
4.3 Medium Salon Booking System Plugin salon-booking-system Broken Access Control Subscriber+ Booking Approval Bypass < 10.30.20 Fixed in 10.30.20 CVE-2026-11887 WPScan
4.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure ≤ 1.4.02 CVE-2026-12113 Wordfence
4.9 Medium Fluent Booking Plugin fluent-booking Information Disclosure Calendar Manager+ Sensitive Information Disclosure via Attendee Export < 2.1.2 Fixed in 2.1.2 CVE-2026-9576 WPScan
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-57660 Patchstack
6.5 Medium Fluent Booking Plugin fluent-booking Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2026-57638 Patchstack
6.5 Medium Gravity Forms Booking Plugin SQL Injection Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id' ≤ 2.7.1 CVE-2026-2508 Wordfence
6.5 Medium WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Subscriber+ Missing Authorization in Multiple AJAX Handlers < 2.3.1 Fixed in 2.3.1 CVE-2026-9822 WPScan
6.4 Medium Appointment Booking Calendar Plugin creavi-booking-service Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label ≤ 1.4.4 CVE-2026-1856 Wordfence
4.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter ≤ 1.4.01 CVE-2026-12111 Wordfence
6.5 Medium Amelia Plugin ameliabooking Broken Access Control ≤ 2.2 Fixed in 2.2.1 CVE-2026-40795 Patchstack
6.5 Medium Booking Activities Plugin booking-activities Broken Access Control No login needed ≤ 1.16.48.1 Fixed in 1.17.0 CVE-2026-39525 Patchstack
6.2 Medium Dharma Booking Plugin dharma-booking Local File Inclusion WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php No login needed ≤ 2.28.3 CVE-2016-20079 VulnCheck
5.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint No login needed ≤ 1.6.11.8 CVE-2026-6937 Wordfence
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.18 Fixed in 2.1.19 CVE-2026-42751 Patchstack
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Denial of Service Unauthenticated Denial of Service No login needed ≤ 1.6.11.5 CVE-2026-7493 Wordfence
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-25426 Patchstack
4.3 Medium WpBookingly Plugin service-booking-manager Broken Access Control ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-25444 Patchstack
6.3 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-27331 Patchstack
5.3 Medium MotoPress Hotel Booking Plugin motopress-hotel-booking-lite Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action No login needed ≤ 6.0.1 CVE-2026-8684 Wordfence
6.5 Medium WpBookingly Plugin service-booking-manager Broken Access Control ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-27405 Patchstack
5.3 Medium Smart Appointment & Booking Plugin smart-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Cancellation No login needed ≤ 1.0.8 CVE-2026-5693 Wordfence
5.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control No login needed < 5.6.8 Fixed in 5.6.8 CVE-2025-66105 Patchstack
6.5 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Unauthenticated Arbitrary Appointment View, Modification and Deletion No login needed ≤ 1.6.10.6 CVE-2026-4807 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint No login needed ≤ 2.1.2 CVE-2026-6449 Wordfence
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via 'amount' Parameter No login needed ≤ 1.7.06 CVE-2026-4911 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover No login needed ≤ 1.2.63 CVE-2026-6810 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) Plugin Broken Access Control Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 4.1.8 CVE-2026-4109 Wordfence
6.4 Medium Surbma | Booking.com Plugin surbma-bookingcom-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1 CVE-2026-1607 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.5 CVE-2026-39663 Patchstack
5.3 Medium iGMS Direct Booking Plugin igms-direct-booking Broken Access Control No login needed ≤ 1.3 CVE-2026-39652 Patchstack
4.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Information Disclosure Sensitive Data Exposure ≤ 5.6.5 Fixed in 5.6.5 CVE-2026-39572 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-39565 Patchstack
5.9 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting ≤ 1.1.38 Fixed in 1.1.39 CVE-2026-39541 Patchstack
6.4 Medium WP Travel Engine - Travel and Tour Booking Plugin wp-travel-engine Cross-Site Scripting Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode ≤ 6.7.5 CVE-2026-2437 Wordfence
6.5 Medium Amelia Plugin ameliabooking SQL Injection Authenticated (Manager+) SQL Injection via 'sort' Parameter ≤ 2.1.2 CVE-2026-4668 Wordfence
5.3 Medium Truebooker - Appointment Booking and Scheduler Plugin truebooker-appointment-booking Information Disclosure Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files No login needed ≤ 1.1.4 CVE-2026-1797 Wordfence
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-23972 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only