WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 402 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-66530 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode ≤ 10.14.6 CVE-2025-12804 Wordfence
4.3 Medium Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution Plugin fluent-booking Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management ≤ 1.9.11 CVE-2025-13756 Wordfence
4.9 Medium Bookme Plugin bookme-free-appointment-booking-system SQL Injection Authenticated (Admin+) SQL Injection via 'filter[status]' Parameter ≤ 4.2 CVE-2025-13385 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter No login needed ≤ 1.2.60 CVE-2025-13318 Wordfence
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter No login needed ≤ 1.3.96 CVE-2025-13317 Wordfence
6.4 Medium HotelRunner Booking Widget Plugin hotelrunner Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.4 CVE-2025-13135 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
6.5 Medium Booking Calendar Plugin booking Cross-Site Scripting ≤ 10.14.7 Fixed in 10.14.8 CVE-2025-64381 Patchstack
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.17 Fixed in 2.1.18 CVE-2025-64275 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed ≤ 1.1.27 CVE-2025-12788 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed ≤ 1.1.27 CVE-2025-12787 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Broken Access Control Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation ≤ 4.2.0.0 CVE-2025-12498 Wordfence
5.3 Medium Course Booking System Plugin course-booking-system Broken Access Control Missing Authorization to Unauthenticated Booking Data Export No login needed ≤ 6.1.5 CVE-2025-12042 Wordfence
5.3 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Broken Access Control No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-5803 Patchstack
5.4 Medium Flights & Hotels Booking WP Plugin adiaha-hotel Broken Access Control ≤ 3.1 CVE-2025-62916 Patchstack
6.3 Medium Hydra Booking Plugin hydra-booking Broken Access Control ≤ 1.1.9 Fixed in 1.1.10 CVE-2025-49377 Patchstack
4.5 Medium Booking Manager Plugin booking-manager Broken Access Control Contributor+ Booking Deletion < 2.1.15 Fixed in 2.1.15 CVE-2025-10124 WPScan
6.5 Medium Easy Hotel Booking Plugin easy-hotel Cross-Site Scripting ≤ 1.9.0 CVE-2025-57938 Patchstack
4.3 Medium Advanced Appointment Booking & Scheduling Plugin advanced-appointment-booking-scheduling Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-57978 Patchstack
5.9 Medium eZee Online Hotel Booking Engine Plugin online-booking-engine Cross-Site Scripting ≤ 1.0.0 CVE-2025-58661 Patchstack
5.3 Medium Salon Booking System Plugin salon-booking-system Broken Access Control Missing Authorization to Unauthenticated AJAX Actions Execution No login needed ≤ 10.22 CVE-2025-8492 Wordfence
6.5 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Broken Access Control ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-39541 Patchstack
6.5 Medium Course Booking Platform Plugin course-booking-platform Cross-Site Scripting ≤ 1.0.0 CVE-2025-58887 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.21 Fixed in 1.1.22 CVE-2025-58633 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.14.1 CVE-2025-9346 Wordfence
6.5 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting ≤ 1.0.14 Fixed in 1.0.15 CVE-2025-58213 Patchstack
6.5 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 5.1.20 Fixed in 5.1.22 CVE-2025-54040 Patchstack
5.9 Medium Webba Booking Plugin webba-booking-lite Cross-Site Scripting ≤ 6.0.5 Fixed in 6.0.6 CVE-2025-54729 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.5 CVE-2025-54676 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
4.3 Medium CBX Restaurant Booking Plugin Cross-Site Request Forgery Plugin Reset via CSRF No login needed ≤ 1.2.1 CVE-2025-7965 WPScan
4.3 Medium Webba Booking Plugin webba-booking-lite Cross-Site Request Forgery No login needed ≤ 5.1.20 Fixed in 5.1.21 CVE-2025-54036 Patchstack
6.5 Medium WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 6.7.16 CVE-2025-3780 Wordfence
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
5.9 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-30637 Patchstack
4.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Request Forgery No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2025-49332 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2025-47585 Patchstack
5.3 Medium Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking Plugin easync-booking Broken Access Control eaSYNC Booking <= 1.3.21 - Insecure Direct Object Reference to Sensitive Information Exposure No login needed ≤ 1.3.21 CVE-2025-4691 Wordfence
4.3 Medium Bellevue Theme bellevuex Broken Access Control ≤ 4.2.2 CVE-2025-39398 Patchstack
4.3 Medium Car Park Booking System Plugin car-park-booking-system-for-wordpress Broken Access Control ≤ 2.6 CVE-2025-39376 Patchstack
5.4 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery CSRF to Arbitrary Content Deletion No login needed ≤ 10.16 Fixed in 10.17 CVE-2025-47583 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode ≤ 10.11.1 CVE-2025-4669 Wordfence
4.3 Medium Salon Booking Pro Plugin salon-booking-plugin-pro-cc Broken Access Control ≤ 10.10.2 CVE-2025-32295 Patchstack
4.3 Medium QuickCal - Appointment Booking Calendar Plugin quickcal Information Disclosure Sensitive Data Exposure ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32299 Patchstack
6.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update 3.4.9 – < 3.5.0 Fixed in 3.5.0 CVE-2024-4665 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only