WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 251–300 of 675 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Booking Calendar Contact Form | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover No login needed |
≤ 1.2.63 |
CVE-2026-6810 |
Wordfence | |
| 6.5 Medium | Taxi Booking Manager for WooCommerce | Cross-Site Scripting |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2026-28040 |
Patchstack | |
| 4.3 Medium | Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) | Broken Access Control Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure |
≤ 4.1.8 |
CVE-2026-4109 |
Wordfence | |
| 6.4 Medium | Surbma | Booking.com | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.1 |
CVE-2026-1607 |
Wordfence | |
| 5.3 Medium | Online Scheduling and Appointment Booking System – Bookly | Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed |
≤ 27.0 |
CVE-2026-2519 |
Wordfence | |
| 5.3 Medium | Pinpoint Booking System | Broken Access Control No login needed |
≤ 2.9.9.6.5 |
CVE-2026-39678 |
Patchstack | |
| 5.3 Medium | TrueBooker | Broken Access Control No login needed |
≤ 1.1.5 |
CVE-2026-39663 |
Patchstack | |
| 5.3 Medium | iGMS Direct Booking | Broken Access Control No login needed |
≤ 1.3 |
CVE-2026-39652 |
Patchstack | |
| 4.3 Medium | Bus Ticket Booking with Seat Reservation | Information Disclosure Sensitive Data Exposure |
≤ 5.6.5 Fixed in 5.6.5 |
CVE-2026-39572 |
Patchstack | |
| 4.3 Medium | WpTravelly | Broken Access Control |
≤ 2.1.7 Fixed in 2.1.8 |
CVE-2026-39565 |
Patchstack | |
| 5.9 Medium | Hydra Booking | Cross-Site Scripting |
≤ 1.1.38 Fixed in 1.1.39 |
CVE-2026-39541 |
Patchstack | |
| 7.6 High | Amelia | SQL Injection |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2026-39487 |
Patchstack | |
| 8.8 High | Amelia | Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter |
≤ 2.1.3 |
CVE-2026-5465 |
Wordfence | |
| 6.4 Medium | WP Travel Engine - Travel and Tour Booking | Cross-Site Scripting Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode |
≤ 6.7.5 |
CVE-2026-2437 |
Wordfence | |
| 6.5 Medium | Amelia | SQL Injection Authenticated (Manager+) SQL Injection via 'sort' Parameter |
≤ 2.1.2 |
CVE-2026-4668 |
Wordfence | |
| 5.3 Medium | Truebooker - Appointment Booking and Scheduler | Information Disclosure Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files No login needed |
≤ 1.1.4 |
CVE-2026-1797 |
Wordfence | |
| 7.2 High | Fluent Booking | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed |
≤ 2.0.01 |
CVE-2026-2231 |
Wordfence | |
| 8.8 High | Amelia Booking | Broken Access Control Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change |
≤ 9.1.2 |
CVE-2026-2931 |
Wordfence | |
| 7.1 High | Bookly | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ <= 26.7 Fixed in 26.8 |
CVE-2026-32540 |
Patchstack | |
| 9.8 Critical | Bus Ticket Booking with Seat Reservation | PHP Object Injection No login needed |
≤ 5.6.0 |
CVE-2026-27095 |
Patchstack | |
| 7.1 High | Booking calendar, Appointment Booking System | Cross-Site Scripting No login needed |
≤ 3.2.36 |
CVE-2026-25435 |
Patchstack | |
| 8.1 High | Salon Booking System Pro | Privilege Escalation Account Takeover No login needed |
≤ 10.30.12 Fixed in 10.30.12 |
CVE-2026-25334 |
Patchstack | |
| 6.5 Medium | Booking and Rental Manager | Broken Access Control |
≤ 2.6.0 Fixed in 2.6.1 |
CVE-2026-23972 |
Patchstack | |
| 7.2 High | Vagaro Booking Widget | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' No login needed |
≤ 0.3 |
CVE-2026-3003 |
Wordfence | |
| 7.5 High | Appointment Booking Calendar | SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed |
≤ 1.6.10.0 |
CVE-2026-3658 |
Wordfence | |
| 5.3 Medium | Travel Booking | Broken Access Control No login needed |
≤ 1.3.9 Fixed in 1.4.0 |
CVE-2026-32486 |
Patchstack | |
| 5.3 Medium | WP Time Slots Booking Form | Broken Access Control No login needed |
≤ 1.2.42 Fixed in 1.2.43 |
CVE-2026-32432 |
Patchstack | |
| 7.5 High | WpBookingly | Local File Inclusion |
≤ 1.2.9 Fixed in 1.3.0 |
CVE-2026-32384 |
Patchstack | |
| 7.6 High | Booking Calendar | SQL Injection |
≤ 10.14.15 Fixed in 10.14.16 |
CVE-2026-32358 |
Patchstack | |
| 7.5 High | Appointment Booking Calendar | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed |
≤ 1.6.9.29 |
CVE-2026-3045 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar | Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure |
≤ 1.6.9.29 |
CVE-2026-1704 |
Wordfence | |
| 4.3 Medium | Timetics | Broken Access Control Unauthenticated Payment/Booking Status Update No login needed |
< 1.0.52 Fixed in 1.0.52 |
CVE-2025-15473 |
WPScan | |
| 7.5 High | JetBooking | SQL Injection Unauthenticated SQL Injection via 'check_in_date' Parameter No login needed |
≤ 4.0.3 |
CVE-2026-3496 |
Wordfence | |
| 7.5 High | Appointment Booking Calendar | SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed |
≤ 1.6.9.27 |
CVE-2026-1708 |
Wordfence | |
| 6.1 Medium | LatePoint – Calendar Booking Plugin for Appointments and Events | Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed |
≤ 5.2.7 |
CVE-2026-2324 |
Wordfence | |
| 8.5 High | Eagle Booking | SQL Injection |
≤ 1.3.4.3 |
CVE-2026-27428 |
Patchstack | |
| 8.8 High | WeDesignTech Ultimate Booking Addon | Privilege Escalation Account Takeover |
≤ 1.0.1 |
CVE-2026-27390 |
Patchstack | |
| 9.8 Critical | WeDesignTech Ultimate Booking Addon | Privilege Escalation Account Takeover No login needed |
≤ 1.0.1 |
CVE-2026-27389 |
Patchstack | |
| 7.5 High | DesignThemes Booking Manager | Broken Access Control No login needed |
≤ 2.0 |
CVE-2026-27388 |
Patchstack | |
| 7.2 High | Amelia | Privilege Escalation |
≤ 1.2.38 Fixed in 2.0 |
CVE-2026-24963 |
Patchstack | |
| 7.5 High | WeDesignTech Ultimate Booking Addon | Broken Access Control No login needed |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2025-69340 |
Patchstack | |
| 5.8 Medium | WP Booking System | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.0.19.12 Fixed in 2.0.19.13 |
CVE-2025-68515 |
Patchstack | |
| 6.5 Medium | Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() |
≤ 1.6.0 |
CVE-2026-1674 |
Wordfence | |
| 8.8 High | Booking and Rental Manager | PHP Object Injection |
≤ 2.5.9 Fixed in 2.6.0 |
CVE-2025-69328 |
Patchstack | |
| 6.5 Medium | Easy Hotel Booking | Broken Access Control |
≤ 1.9.2 |
CVE-2025-68005 |
Patchstack | |
| 5.9 Medium | Schedula | Broken Access Control No login needed |
≤ 1.0 Fixed in 1.1 |
CVE-2025-67970 |
Patchstack | |
| 4.4 Medium | Tennis Court Bookings | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters |
≤ 1.2.7 |
CVE-2026-1044 |
Wordfence | |
| 4.3 Medium | Booking Calendar | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification |
≤ 10.14.14 |
CVE-2026-2230 |
Wordfence | |
| 4.9 Medium | Bookster – WordPress Appointment Booking | SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' |
≤ 2.1.1 |
CVE-2025-8781 |
Wordfence | |
| 4.3 Medium | LatePoint – Calendar Booking Plugin for Appointments and Events | Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed |
≤ 5.2.5 |
CVE-2025-14873 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.