WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 402 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Travel Booking Plugin travel-booking Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2026-32486 Patchstack
5.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control No login needed ≤ 1.2.42 Fixed in 1.2.43 CVE-2026-32432 Patchstack
4.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure ≤ 1.6.9.29 CVE-2026-1704 Wordfence
4.3 Medium Timetics Plugin timetics Broken Access Control Unauthenticated Payment/Booking Status Update No login needed < 1.0.52 Fixed in 1.0.52 CVE-2025-15473 WPScan
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
5.8 Medium WP Booking System Plugin wp-booking-system Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.19.12 Fixed in 2.0.19.13 CVE-2025-68515 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
6.5 Medium Easy Hotel Booking Plugin easy-hotel Broken Access Control ≤ 1.9.2 CVE-2025-68005 Patchstack
5.9 Medium Schedula Plugin schedula-smart-appointment-booking Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-67970 Patchstack
4.4 Medium Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters ≤ 1.2.7 CVE-2026-1044 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification ≤ 10.14.14 CVE-2026-2230 Wordfence
4.9 Medium Bookster – WordPress Appointment Booking Plugin bookster SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' ≤ 2.1.1 CVE-2025-8781 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence
5.3 Medium Appointment Booking Calendar Plugin bookr Broken Access Control Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification No login needed ≤ 1.0.2 CVE-2026-1932 Wordfence
5.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure No login needed ≤ 5.2.6 CVE-2026-1537 Wordfence
6.4 Medium Smart Appointment & Booking Plugin smart-appointment-booking Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action ≤ 1.0.7 CVE-2026-0742 Wordfence
5.3 Medium Amelia Plugin ameliabooking Broken Access Control No login needed ≤ 1.2.38 Fixed in 2.0 CVE-2026-24967 Patchstack
4.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed < 2.7.9 Fixed in 2.7.9 CVE-2026-0658 WPScan
5.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed ≤ 10.14.13 CVE-2026-1431 Wordfence
4.4 Medium Appointment Hour Booking – Booking Calendar Plugin appointment-hour-booking Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration ≤ 1.5.60 CVE-2026-1083 Wordfence
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
6.5 Medium Bookingor Plugin bookingor Broken Access Control Subscriber+ Category Deletion ≤ 1.0.12 CVE-2025-12573 WPScan
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Information Disclosure Unauthenticated Sensitive Information Exposure via 'email' Parameter No login needed ≤ 2.2.7 CVE-2025-14075 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 10.14.11 CVE-2025-14982 Wordfence
5.3 Medium EventPrime - Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Information Disclosure Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.0 CVE-2025-14507 Wordfence
5.3 Medium Booking Calendar Plugin booking Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 10.14.10 CVE-2025-14146 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
5.3 Medium Awesome Hotel Booking Plugin Broken Access Control Incorrect Authorization to Unauthenticated Arbitrary Booking Modification No login needed ≤ 1.0.3 CVE-2025-14352 Wordfence
5.4 Medium WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69341 Patchstack
6.5 Medium Appointment Booking and Scheduling Calendar Plugin – WP Timetics Plugin timetics Broken Access Control WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification No login needed ≤ 1.0.36 CVE-2025-5919 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.5 CVE-2025-11723 Wordfence
6.5 Medium AweBooking Plugin awebooking Information Disclosure Sensitive Data Exposure ≤ 3.2.26 CVE-2025-68014 Patchstack
5.3 Medium Hotel Booking Plugin nd-booking Broken Access Control No login needed ≤ 3.8 CVE-2025-63001 Patchstack
5.4 Medium Eagle Booking Plugin eagle-booking Broken Access Control Settings Change ≤ 1.3.4.3 CVE-2025-68976 Patchstack
4.3 Medium Eagle Booking Plugin eagle-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.4.3 CVE-2025-68975 Patchstack
6.5 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.2.39 Fixed in 1.2.40 CVE-2025-68569 Patchstack
6.1 Medium Five Star Restaurant Reservations – WordPress Booking Plugin Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2025-11496 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
5.9 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-49918 Patchstack
4.3 Medium Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed ≤ 7.2.2.2 CVE-2025-12407 Wordfence
4.3 Medium Simple Bike Rental Plugin simple-bike-rental Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Booking Data Exposure ≤ 1.0.6 CVE-2025-14065 Wordfence
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Information Disclosure Sensitive Data Exposure ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-63013 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63012 Patchstack
5.9 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63011 Patchstack
4.3 Medium Fluent Booking Plugin fluent-booking Broken Access Control ≤ 1.9.11 Fixed in 1.10.0 CVE-2025-67597 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-67581 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-67574 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67559 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only