WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Appointment Booking Calendar Plugin bookr Broken Access Control Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification No login needed ≤ 1.0.2 CVE-2026-1932 Wordfence
5.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure No login needed ≤ 5.2.6 CVE-2026-1537 Wordfence
6.4 Medium Smart Appointment & Booking Plugin smart-appointment-booking Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action ≤ 1.0.7 CVE-2026-0742 Wordfence
5.3 Medium Amelia Plugin ameliabooking Broken Access Control No login needed ≤ 1.2.38 Fixed in 2.0 CVE-2026-24967 Patchstack
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
4.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed < 2.7.9 Fixed in 2.7.9 CVE-2026-0658 WPScan
5.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed ≤ 10.14.13 CVE-2026-1431 Wordfence
4.4 Medium Appointment Hour Booking – Booking Calendar Plugin appointment-hour-booking Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration ≤ 1.5.60 CVE-2026-1083 Wordfence
7.3 High Hydra Booking Plugin hydra-booking Privilege Escalation No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68027 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Information Disclosure Sensitive Data Exposure ≤ 1.1.23 CVE-2025-68006 Patchstack
8.6 High Movie Booking Plugin movie-booking Arbitrary File Deletion No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-67963 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Information Disclosure Sensitive Data Exposure ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-67954 Patchstack
8.1 High Booking Activities Plugin booking-activities Privilege Escalation No login needed ≤ 1.16.44 Fixed in 1.16.45 CVE-2025-67953 Patchstack
6.5 Medium Bookingor Plugin bookingor Broken Access Control Subscriber+ Category Deletion ≤ 1.0.12 CVE-2025-12573 WPScan
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Information Disclosure Unauthenticated Sensitive Information Exposure via 'email' Parameter No login needed ≤ 2.2.7 CVE-2025-14075 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 10.14.11 CVE-2025-14982 Wordfence
5.3 Medium EventPrime - Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Information Disclosure Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.0 CVE-2025-14507 Wordfence
7.2 High Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) Plugin wp-event-solution Broken Access Control Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings' No login needed ≤ 4.0.51 CVE-2025-14657 Wordfence
5.3 Medium Booking Calendar Plugin booking Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 10.14.10 CVE-2025-14146 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
5.3 Medium Awesome Hotel Booking Plugin Broken Access Control Incorrect Authorization to Unauthenticated Arbitrary Booking Modification No login needed ≤ 1.0.3 CVE-2025-14352 Wordfence
5.4 Medium WeDesignTech Ultimate Booking Addon Plugin wedesigntech-ultimate-booking-addon Broken Access Control ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-69341 Patchstack
6.5 Medium Appointment Booking and Scheduling Calendar Plugin – WP Timetics Plugin timetics Broken Access Control WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification No login needed ≤ 1.0.36 CVE-2025-5919 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.5 CVE-2025-11723 Wordfence
7.5 High Booking Package Plugin booking-package Price Manipulation No login needed ≤ 1.6.27 Fixed in 1.6.29 CVE-2024-30516 Patchstack
6.5 Medium AweBooking Plugin awebooking Information Disclosure Sensitive Data Exposure ≤ 3.2.26 CVE-2025-68014 Patchstack
5.3 Medium Hotel Booking Plugin nd-booking Broken Access Control No login needed ≤ 3.8 CVE-2025-63001 Patchstack
5.4 Medium Eagle Booking Plugin eagle-booking Broken Access Control Settings Change ≤ 1.3.4.3 CVE-2025-68976 Patchstack
4.3 Medium Eagle Booking Plugin eagle-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.4.3 CVE-2025-68975 Patchstack
6.5 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.2.39 Fixed in 1.2.40 CVE-2025-68569 Patchstack
6.1 Medium Five Star Restaurant Reservations – WordPress Booking Plugin Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2025-11496 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
9.1 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite Remote Code Execution ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-66078 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
5.9 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-49918 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.32 Fixed in 1.1.33 CVE-2025-68055 Patchstack
7.5 High Booking Calendar Plugin booking SQL Injection Unauthenticated SQL Injection via dates_to_check No login needed ≤ 10.14.8 CVE-2025-14383 Wordfence
4.3 Medium Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed ≤ 7.2.2.2 CVE-2025-12407 Wordfence
4.3 Medium Simple Bike Rental Plugin simple-bike-rental Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Booking Data Exposure ≤ 1.0.6 CVE-2025-14065 Wordfence
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Information Disclosure Sensitive Data Exposure ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-63013 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63012 Patchstack
5.9 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63011 Patchstack
4.3 Medium Fluent Booking Plugin fluent-booking Broken Access Control ≤ 1.9.11 Fixed in 1.10.0 CVE-2025-67597 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-67581 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-67574 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67559 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-66530 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode ≤ 10.14.6 CVE-2025-12804 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only