WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 201–250 of 275 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Omnishop Plugin omnishop Broken Access Control Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint No login needed ≤ 1.0.9 CVE-2025-6215 Wordfence
6.4 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 1.6.8.30 CVE-2025-4667 Wordfence
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
4.3 Medium CubePoints Plugin cubepoints Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-28952 Patchstack
4.3 Medium QuickCal - Appointment Booking Calendar Plugin quickcal Information Disclosure Sensitive Data Exposure ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32299 Patchstack
5.3 Medium Latepoint Plugin latepoint Broken Access Control Unauthenticated Insecure Direct Object Reference No login needed ≤ 5.1.92 CVE-2025-3769 Wordfence
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-47543 Patchstack
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46247 Patchstack
4.3 Medium Easy!Appointments Plugin easyappointments Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-31828 Patchstack
6.5 Medium Appointy Appointment Scheduler Plugin appointy-appointment-scheduler Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 4.2.1 CVE-2025-31601 Patchstack
6.6 Medium Appointify Plugin appointify Arbitrary File Upload ≤ 1.0.8 CVE-2025-31577 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2.19 CVE-2025-2578 Wordfence
5.4 Medium Easy Booked – Appointment Booking and Scheduling Management System Plugin easy-booked Cross-Site Request Forgery No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-22634 Patchstack
6.5 Medium LatePoint Plugin latepoint Cross-Site Scripting ≤ 5.1.6 Fixed in 5.1.7 CVE-2025-30836 Patchstack
6.1 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.3 CVE-2024-13431 Wordfence
6.4 Medium Point Maker Plugin point-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.6 CVE-2024-12815 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected XSS No login needed < 5.0.0 Fixed in 5.0.0 CVE-2024-12737 WPScan
6.5 Medium Pinpoint Booking System – #1 WordPress Booking Plugin booking-system SQL Injection #1 WordPress Booking Plugin <= 2.9.9.5.4 - Authenticated (Subscriber+) SQL Injection ≤ 2.9.9.5.4 CVE-2024-13235 Wordfence
6.4 Medium Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files Plugin embed-any-document Server-Side Request Forgery Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode ≤ 2.7.5 CVE-2025-1043 Wordfence
4.9 Medium SuperSaaS – online appointment scheduling Plugin supersaas-appointment-scheduling Cross-Site Scripting online appointment scheduling <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via after Parameter ≤ 2.1.12 CVE-2025-0862 Wordfence
6.5 Medium BookingPress Plugin bookingpress-appointment-booking Cross-Site Scripting ≤ 1.1.25 Fixed in 1.1.26 CVE-2025-24732 Patchstack
4.3 Medium Point Theme point Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-37931 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2023-45649 Patchstack
6.5 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection ≤ 1.1.21 CVE-2024-11726 Wordfence
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control ≤ 1.1.12 Fixed in 1.1.13 CVE-2023-32601 Patchstack
4.3 Medium WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 1.0.27 CVE-2024-11275 Wordfence
6.1 Medium Ultimate Endpoints With Rest Api Plugin custom-wp-rest-api Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.2 CVE-2024-12260 Wordfence
5.0 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24407 Patchstack
4.3 Medium Easy Appointments Plugin easy-appointments Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) No login needed ≤ 3.10.7 Fixed in 3.11.1 CVE-2023-30748 Patchstack
6.4 Medium myCred – Loyalty Points and Rewards Plugin mycred Cross-Site Scripting Loyalty Points and Rewards plugin <= 2.7.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode ≤ 2.7.5.2 CVE-2024-11201 Wordfence
6.5 Medium Gmap Point List Plugin gmap-point-list Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.2 CVE-2024-51594 Patchstack
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
4.3 Medium UPS Live Rates and Access Points Plugin flexible-shipping-ups Broken Access Control Missing Authorization to Plugin API key reset ≤ 2.3.12 CVE-2024-9109 Wordfence
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
6.5 Medium LatePoint Plugin Cross-Site Scripting ≤ 4.9.91 CVE-2024-43992 Patchstack
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
5.3 Medium LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… Plugin ladipage Broken Access Control Missing Authorization via init_endpoint No login needed ≤ 4.3 CVE-2023-4730 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
5.4 Medium Pinpoint Booking System Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.9.9.4.8 Fixed in 2.9.9.4.8 CVE-2024-3636 WPScan
6.5 Medium SuperSaaS – online appointment scheduling Plugin supersaas-appointment-scheduling Cross-Site Scripting online appointment scheduling plugin <= 2.1.9 - Cross Site Scripting (XSS) ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-37460 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only