WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Unauthenticated Stored XSS via Booking Customer Information No login needed < 1.6.12.4 Fixed in 1.6.12.4 CVE-2026-13400 WPScan
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter No login needed ≤ 1.8.13 CVE-2026-15401 Wordfence
6.1 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross-Site Scripting via 'category_id' Parameter No login needed ≤ 1.8.13 CVE-2026-15346 Wordfence
6.4 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute ≤ 2.3.2 CVE-2026-15464 Wordfence
6.5 Medium Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting ≤ 1.5.86 Fixed in 1.5.87 CVE-2026-65514 Patchstack
5.3 Medium JetBooking Plugin jet-booking Broken Access Control No login needed ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65468 Patchstack
4.9 Medium JetBooking Plugin jet-booking Server-Side Request Forgery ≤ 4.1.2 Fixed in 4.1.2.1 CVE-2026-65466 Patchstack
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-61951 Patchstack
9.3 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2026-61950 Patchstack
9.3 Critical Bookly Plugin bookly-responsive-appointment-booking-tool SQL Injection No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61949 Patchstack
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting No login needed ≤ 27.7 Fixed in 27.8 CVE-2026-61944 Patchstack
8.8 High WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Privilege Escalation ≤ 6.3.1 Fixed in 6.3.2 CVE-2026-59541 Patchstack
7.1 High WP Booking System Plugin wp-booking-system-premium Broken Access Control < 5.12.8.1 Fixed in 5.12.8.1 CVE-2026-57367 Patchstack
6.7 Medium QuickCal - Appointment Booking Calendar Plugin quickcal Broken Access Control Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control ≤ 1.0.16 CVE-2026-27377 Patchstack
5.3 Medium Timetics Plugin timetics Broken Access Control Unauthenticated Booking Auto-Approval via Arbitrary payment_method No login needed < 1.0.57 Fixed in 1.0.57 CVE-2026-14322 WPScan
7.5 High Events Manager Plugin events-manager SQL Injection Unauthenticated SQL Injection via PHP Object Injection in Booking Registration No login needed < 7.3.7 Fixed in 7.3.7 CVE-2026-12987 WPScan
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 11.7.1 Fixed in 11.7.1 CVE-2026-11868 WPScan
5.4 Medium WPS Bookings for WooCommerce Plugin mwb-bookings-for-woocommerce Broken Access Control Subscriber+ Arbitrary Booking Order Cancellation via IDOR < 3.11.7 Fixed in 3.11.7 CVE-2026-12393 WPScan
6.1 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Reflected Cross-Site Scripting via 'check_in_date' Parameter No login needed ≤ 2.3.2 CVE-2026-15094 Wordfence
4.9 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import ≤ 2.4.3 CVE-2026-14782 Wordfence
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.36 CVE-2026-57778 Patchstack
9.3 Critical Amelia Plugin ameliabooking SQL Injection No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-57702 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2026-57404 Patchstack
7.1 High Hydra Booking Plugin hydra-booking Cross-Site Scripting No login needed ≤ 1.1.44 Fixed in 1.1.45 CVE-2026-57388 Patchstack
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler No login needed ≤ 2.3.1 CVE-2026-11901 Wordfence
7.5 High Booking Package Plugin booking-package SQL Injection Unauthenticated SQL Injection via 'email' Form Parameter No login needed ≤ 1.7.20 CVE-2026-15335 Wordfence
5.9 Medium Booking calendar, Appointment Booking System Plugin booking-calendar SQL Injection Unauthenticated Time-Based SQL Injection via 'wpdevart_id' No login needed ≤ 3.2.17 CVE-2026-15289 Wordfence
6.1 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters No login needed ≤ 2.3.1 CVE-2026-11392 Wordfence
8.8 High Salon Booking System Plugin salon-booking-system Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter No login needed ≤ 10.30.32 CVE-2026-15070 Wordfence
4.3 Medium Hydra Booking Plugin hydra-booking Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter ≤ 1.2.1 CVE-2026-12433 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field No login needed ≤ 1.8.8 CVE-2026-6820 Wordfence
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter No login needed ≤ 1.8.8 CVE-2026-6818 Wordfence
8.1 High BookingPress Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.1.28 CVE-2026-12378 WPScan
5.3 Medium LatePoint Plugin latepoint Broken Access Control Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step No login needed ≤ 5.6.1 CVE-2026-11398 Wordfence
5.3 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite Broken Access Control Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter No login needed ≤ 2.4.4 CVE-2026-9180 Wordfence
6.5 Medium Hotel Booking Lite Plugin motopress-hotel-booking-lite Information Disclosure Sensitive Data Exposure ≤ 6.0.3 Fixed in 6.0.4 CVE-2026-57347 Patchstack
5.3 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Broken Access Control Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter No login needed ≤ 2.7.6 CVE-2026-9188 Wordfence
7.4 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2026-57723 Patchstack
5.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 6.4.13 Fixed in 6.4.14 CVE-2026-27409 Patchstack
6.1 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross-Site Scripting via 'layoutstyle' Parameter No login needed ≤ 1.8.12 CVE-2026-12754 Wordfence
6.5 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite SQL Injection Authenticated (Staff+) SQL Injection via 's' Parameter ≤ 2.4.5 CVE-2026-13454 Wordfence
4.3 Medium Salon Booking System Plugin salon-booking-system Broken Access Control Subscriber+ Booking Approval Bypass < 10.30.20 Fixed in 10.30.20 CVE-2026-11887 WPScan
7.5 High BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection Unauthenticated SQL Injection via 'store_service_date' Parameter No login needed ≤ 5.7.1 CVE-2026-11823 Wordfence
4.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure ≤ 1.4.02 CVE-2026-12113 Wordfence
4.9 Medium Fluent Booking Plugin fluent-booking Information Disclosure Calendar Manager+ Sensitive Information Disclosure via Attendee Export < 2.1.2 Fixed in 2.1.2 CVE-2026-9576 WPScan
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-57660 Patchstack
6.5 Medium Fluent Booking Plugin fluent-booking Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2026-57638 Patchstack
9.9 Critical Travel Booking Theme travel-booking Arbitrary File Upload ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-56059 Patchstack
9.3 Critical JetBooking Plugin jet-booking SQL Injection No login needed ≤ 4.0.4.1 Fixed in 4.0.4.2 CVE-2026-54820 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only