WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 251–300 of 471 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Complianz – GDPR/CCPA Cookie Consent Plugin complianz-gdpr Broken Access Control GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint No login needed ≤ 7.4.5 CVE-2026-4019 Wordfence
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability ≤ 5.4.1 CVE-2026-6741 Wordfence
5.3 Medium Liaison Site Prober Plugin liaison-site-prober Broken Access Control Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint No login needed ≤ 1.2.1 CVE-2026-3569 Wordfence
7.5 High Easy Appointments Plugin easy-appointments Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 3.12.21 CVE-2026-2262 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID No login needed ≤ 5.3.2 CVE-2026-5234 Wordfence
5.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Price Manipulation Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' No login needed ≤ 27.0 CVE-2026-2519 Wordfence
5.3 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.10.2 CVE-2026-39694 Patchstack
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.5 CVE-2026-39663 Patchstack
9.6 Critical Appointment Plugin appointment Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 3.5.5 CVE-2026-39620 Patchstack
8.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39495 Patchstack
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint No login needed ≤ 2.1.7 CVE-2026-5167 Wordfence
5.3 Medium Riaxe Product Customizer Plugin riaxe-product-customizer Information Disclosure Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint No login needed ≤ 2.4 CVE-2026-3594 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.3.0 CVE-2026-4785 Wordfence
5.3 Medium Truebooker - Appointment Booking and Scheduler Plugin truebooker-appointment-booking Information Disclosure Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files No login needed ≤ 1.1.4 CVE-2026-1797 Wordfence
7.1 High Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ <= 26.7 Fixed in 26.8 CVE-2026-32540 Patchstack
6.5 Medium LatePoint Plugin latepoint Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ <= 5.2.6 Fixed in 5.2.7 CVE-2026-32533 Patchstack
7.1 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting No login needed ≤ 3.2.36 CVE-2026-25435 Patchstack
5.3 Medium Appmax Plugin appmax Broken Access Control Missing Authorization to Order Status Manipulation and Arbitrary Order Creation via Webhook Endpoint No login needed ≤ 1.0.3 CVE-2026-3641 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'fields' Parameter No login needed ≤ 1.6.10.0 CVE-2026-3658 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
4.3 Medium Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure ≤ 1.6.9.29 CVE-2026-1704 Wordfence
6.5 Medium wpDiscuz Plugin wpdiscuz Other No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22216 VulnCheck
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
6.1 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting No login needed ≤ 5.2.7 CVE-2026-2324 Wordfence
5.3 Medium Booktics Plugin booktics Broken Access Control Missing Authorization to Get Items via REST API endpoints No login needed ≤ 1.0.16 CVE-2026-1919 Wordfence
7.2 High PostX Plugin ultimate-post Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints No login needed ≤ 5.0.8 CVE-2026-1273 Wordfence
6.5 Medium LatePoint Plugin SQL Injection Authenticated (Administrator+) SQL Injection via JSON Import ≤ 5.2.7 CVE-2026-1487 Wordfence
8.8 High LatePoint Plugin Privilege Escalation Authenticated (Agent+) Privilege Escalation ≤ 5.2.7 CVE-2026-1566 Wordfence
10.0 Critical ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor Plugin elementskit-lite Broken Access Control ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint No login needed < 3.7.9 Fixed in 3.7.9 CVE-2026-23693 VulnCheck
5.9 Medium Schedula Plugin schedula-smart-appointment-booking Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-67970 Patchstack
4.9 Medium Bookster – WordPress Appointment Booking Plugin bookster SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' ≤ 2.1.1 CVE-2025-8781 Wordfence
5.3 Medium YayMail Plugin yaymail Broken Access Control Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint No login needed ≤ 4.3.2 CVE-2026-1938 Wordfence
4.3 Medium Gutenberg Blocks with AI by Kadence WP Plugin kadence-blocks Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter ≤ 3.6.1 CVE-2026-1857 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint No login needed ≤ 4.2.8.4 CVE-2026-1657 Wordfence
4.9 Medium Mail Mint Plugin mail-mint SQL Injection Authenticated (Administrator+) SQL Injection via Multiple API Endpoints ≤ 1.19.2 CVE-2026-1258 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence
5.3 Medium Appointment Booking Calendar Plugin bookr Broken Access Control Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification No login needed ≤ 1.0.2 CVE-2026-1932 Wordfence
5.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure No login needed ≤ 5.2.6 CVE-2026-1537 Wordfence
6.4 Medium Premmerce Plugin premmerce Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint ≤ 1.3.20 CVE-2026-0555 Wordfence
7.2 High All In One Image Viewer Block Plugin image-viewer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via image-proxy Endpoint No login needed ≤ 1.0.2 CVE-2026-1294 Wordfence
8.2 High Popup builder with Gamification Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed ≤ 2.2.0 CVE-2025-13192 Wordfence
6.4 Medium Smart Appointment & Booking Plugin smart-appointment-booking Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action ≤ 1.0.7 CVE-2026-0742 Wordfence
5.3 Medium Fortis for WooCommerce Plugin fortis-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint No login needed ≤ 1.2.0 CVE-2026-0679 Wordfence
6.5 Medium MyRewards – Loyalty Points and Rewards for WooCommerce Plugin woorewards Broken Access Control Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification ≤ 5.6.1 CVE-2025-15260 Wordfence
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
7.2 High AI Engine Plugin ai-engine Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint ≤ 3.3.2 CVE-2026-1400 Wordfence
4.4 Medium Appointment Hour Booking – Booking Calendar Plugin appointment-hour-booking Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration ≤ 1.5.60 CVE-2026-1083 Wordfence
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control ≤ 2.9.5 Fixed in 2.9.6 CVE-2026-24581 Patchstack
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.9.15 Fixed in 1.6.9.17 CVE-2025-69315 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only