WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover No login needed ≤ 1.2.63 CVE-2026-6810 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) Plugin Broken Access Control Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 4.1.8 CVE-2026-4109 Wordfence
6.4 Medium Surbma | Booking.com Plugin surbma-bookingcom-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1 CVE-2026-1607 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.5 CVE-2026-39663 Patchstack
5.3 Medium iGMS Direct Booking Plugin igms-direct-booking Broken Access Control No login needed ≤ 1.3 CVE-2026-39652 Patchstack
4.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Information Disclosure Sensitive Data Exposure ≤ 5.6.5 Fixed in 5.6.5 CVE-2026-39572 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-39565 Patchstack
5.9 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting ≤ 1.1.38 Fixed in 1.1.39 CVE-2026-39541 Patchstack
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-39487 Patchstack
8.8 High Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter ≤ 2.1.3 CVE-2026-5465 Wordfence
6.4 Medium WP Travel Engine - Travel and Tour Booking Plugin wp-travel-engine Cross-Site Scripting Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode ≤ 6.7.5 CVE-2026-2437 Wordfence
6.5 Medium Amelia Plugin ameliabooking SQL Injection Authenticated (Manager+) SQL Injection via 'sort' Parameter ≤ 2.1.2 CVE-2026-4668 Wordfence
5.3 Medium Truebooker - Appointment Booking and Scheduler Plugin truebooker-appointment-booking Information Disclosure Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files No login needed ≤ 1.1.4 CVE-2026-1797 Wordfence
7.2 High Fluent Booking Plugin fluent-booking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.0.01 CVE-2026-2231 Wordfence
8.8 High Amelia Booking Plugin ameliabooking Broken Access Control Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change ≤ 9.1.2 CVE-2026-2931 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
9.8 Critical Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation PHP Object Injection No login needed ≤ 5.6.0 CVE-2026-27095 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
8.1 High Salon Booking System Pro Plugin salon-booking-plugin-pro Privilege Escalation Account Takeover No login needed ≤ 10.30.12 Fixed in 10.30.12 CVE-2026-25334 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-23972 Patchstack
7.2 High Vagaro Booking Widget Plugin vagaro-booking-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' No login needed ≤ 0.3 CVE-2026-3003 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
5.3 Medium Travel Booking Plugin travel-booking Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2026-32486 Patchstack
5.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control No login needed ≤ 1.2.42 Fixed in 1.2.43 CVE-2026-32432 Patchstack
7.5 High WpBookingly Plugin service-booking-manager Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32384 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 10.14.15 Fixed in 10.14.16 CVE-2026-32358 Patchstack
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
4.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure ≤ 1.6.9.29 CVE-2026-1704 Wordfence
4.3 Medium Timetics Plugin timetics Broken Access Control Unauthenticated Payment/Booking Status Update No login needed < 1.0.52 Fixed in 1.0.52 CVE-2025-15473 WPScan
7.5 High JetBooking Plugin SQL Injection Unauthenticated SQL Injection via 'check_in_date' Parameter No login needed ≤ 4.0.3 CVE-2026-3496 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
8.5 High Eagle Booking Plugin eagle-booking SQL Injection ≤ 1.3.4.3 CVE-2026-27428 Patchstack
8.8 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2026-27390 Patchstack
9.8 Critical WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2026-27389 Patchstack
7.5 High DesignThemes Booking Manager Plugin designthemes-booking-manager Broken Access Control No login needed ≤ 2.0 CVE-2026-27388 Patchstack
7.2 High Amelia Plugin ameliabooking Privilege Escalation ≤ 1.2.38 Fixed in 2.0 CVE-2026-24963 Patchstack
7.5 High WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69340 Patchstack
5.8 Medium WP Booking System Plugin wp-booking-system Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.19.12 Fixed in 2.0.19.13 CVE-2025-68515 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack
6.5 Medium Easy Hotel Booking Plugin easy-hotel Broken Access Control ≤ 1.9.2 CVE-2025-68005 Patchstack
5.9 Medium Schedula Plugin schedula-smart-appointment-booking Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-67970 Patchstack
4.4 Medium Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters ≤ 1.2.7 CVE-2026-1044 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification ≤ 10.14.14 CVE-2026-2230 Wordfence
4.9 Medium Bookster – WordPress Appointment Booking Plugin bookster SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' ≤ 2.1.1 CVE-2025-8781 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only