WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2023-45649 Patchstack
6.5 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection ≤ 1.1.21 CVE-2024-11726 Wordfence
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
9.3 Critical Instant Appointment Plugin instant-appointment SQL Injection No login needed ≤ 1.2 CVE-2024-54361 Patchstack
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control ≤ 1.1.12 Fixed in 1.1.13 CVE-2023-32601 Patchstack
4.3 Medium WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 1.0.27 CVE-2024-11275 Wordfence
5.0 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24407 Patchstack
4.3 Medium Easy Appointments Plugin easy-appointments Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) No login needed ≤ 3.10.7 Fixed in 3.11.1 CVE-2023-30748 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
7.2 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.2.15 CVE-2024-9504 Wordfence
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection Multiple Unauthenticated SQLi No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6924 WPScan
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
9.8 Critical Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking Authentication Bypass BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover No login needed 1.1.6 – 1.1.7 CVE-2024-7350 Wordfence
6.5 Medium SuperSaaS – online appointment scheduling Plugin supersaas-appointment-scheduling Cross-Site Scripting online appointment scheduling plugin <= 2.1.9 - Cross Site Scripting (XSS) ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-37460 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
8.8 High BookingPress Appointment Booking Plugin bookingpress-appointment-booking Path Traversal Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation ≤ 1.1.5 CVE-2024-6467 Wordfence
8.8 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Broken Access Control Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload ≤ 1.1.5 CVE-2024-6660 Wordfence
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
6.5 Medium Bookster Plugin bookster Broken Access Control Unauthenticated Appointment Status Update ≤ 1.1.0 CVE-2024-5071 WPScan
7.2 High Appointment Booking and Online Scheduling Plugin meeting-scheduler-by-vcita Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5791 Wordfence
6.1 Medium Appointment Booking and Online Scheduling Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5859 Wordfence
7.3 High Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin timetics Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 1.0.21 CVE-2024-1094 Wordfence
6.5 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Appointment Duration Manipulation No login needed ≤ 1.0.82 Fixed in 1.0.83 CVE-2024-34799 Patchstack
6.4 Medium WordPress Online Booking and Scheduling Plugin – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 23.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile Parameter ≤ 23.2 CVE-2024-5584 Wordfence
3.7 Low Booking calendar, Appointment Booking System Plugin booking-calendar Other Bypass No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24373 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Authentication Bypass Captcha Bypass No login needed ≤ 1.4.56 Fixed in 1.4.57 CVE-2024-32720 Patchstack
7.7 High Bookly Plugin bookly-responsive-appointment-booking-tool Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 21.7.1 Fixed in 21.8 CVE-2023-26526 Patchstack
6.4 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7.14 CVE-2024-4288 Wordfence
8.2 High BookingPress Plugin bookingpress-appointment-booking Price Manipulation Booking Price Manipulation No login needed ≤ 1.0.74 Fixed in 1.0.75 CVE-2023-51405 Patchstack
4.4 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Server-Side Request Forgery ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32454 Patchstack
6.3 Medium Easy!Appointments Plugin easyappointments Arbitrary File Deletion ≤ 1.3.3 Fixed in 1.4.0 CVE-2023-32295 Patchstack
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.6.7.7 CVE-2024-2341 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.6.7.7 CVE-2024-2342 Wordfence
4.3 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0.81 Fixed in 1.0.82 CVE-2024-31296 Patchstack
7.2 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Arbitrary File Upload Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.87 CVE-2024-3022 Wordfence
7.1 High Appointment Calendar Plugin appointment-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.6 CVE-2024-30561 Patchstack
4.3 Medium Easy Appointments Plugin easy-appointments Broken Access Control Insufficient Authorization ≤ 3.11.18 CVE-2024-2844 Wordfence
6.4 Medium Easy Appointments Plugin easy-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.11.18 CVE-2024-2842 Wordfence
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6.20 Fixed in 1.6.6.24 CVE-2024-22311 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only