WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 402 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Cross-Site Request Forgery No login needed ≤ 5.4.3 Fixed in 5.4.4 CVE-2024-49294 Patchstack
6.1 Medium Booking Calendar and Booking Calendar Pro <= Multiple Versions Plugin booking-calendar Cross-Site Scripting Reflected Cross-Site Scripting via 'calendar_id' No login needed ≤ 3.2.19, ≤ 11.2.19 CVE-2024-12077 Wordfence
6.4 Medium YOGO Booking Plugin yogo-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.2 CVE-2024-12462 Wordfence
6.1 Medium Tourmaster Plugin Cross-Site Scripting Unauthenticated Stored XSS via Room Booking No login needed < 5.3.4 Fixed in 5.3.4 CVE-2024-11356 WPScan
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2023-45649 Patchstack
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
6.5 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection ≤ 1.1.21 CVE-2024-11726 Wordfence
6.5 Medium Booking Calendar WpDevArt Plugin booking-calendar SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.2.19 CVE-2024-10856 Wordfence
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5 Fixed in 4.5.2 CVE-2024-54356 Patchstack
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control ≤ 1.1.12 Fixed in 1.1.13 CVE-2023-32601 Patchstack
4.3 Medium WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 1.0.27 CVE-2024-11275 Wordfence
6.4 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.6 CVE-2024-11754 Wordfence
4.7 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.1.82 Fixed in 1.1.83 CVE-2023-23895 Patchstack
5.0 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24407 Patchstack
4.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control ≤ 1.2.34 Fixed in 1.2.35 CVE-2023-25037 Patchstack
4.3 Medium WP Booking System Plugin wp-booking-system Broken Access Control ≤ 2.0.19.2 Fixed in 2.0.19.3 CVE-2023-49758 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.5.1 CVE-2024-9872 Wordfence
4.8 Medium WP Booking Calendar Plugin Cross-Site Scripting Admin+ Stored XSS < 10.6.5 Fixed in 10.6.5 CVE-2024-10893 WPScan
6.4 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via beds24-link Shortcode ≤ 2.0.27 CVE-2024-10177 Wordfence
6.5 Medium Multi-day Booking Calendar Plugin multi-day-booking-calendar Cross-Site Scripting ≤ 1.0.1 CVE-2024-51873 Patchstack
6.5 Medium Minical Hotel Booking Plugin minical Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-51895 Patchstack
6.5 Medium EzyOnlineBookings Online Booking System Widget Plugin ezyonlinebookings-online-booking-system Cross-Site Scripting ≤ 1.3 CVE-2024-51628 Patchstack
5.9 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.25 Fixed in 2.0.26 CVE-2024-51664 Patchstack
4.8 Medium WP Booking Calendar Plugin Cross-Site Scripting Admin+ Stored XSS < 10.6.3 Fixed in 10.6.3 CVE-2024-10027 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
6.5 Medium WP Booking System Plugin wp-booking-system Broken Access Control Booking Calendar plugin <= 2.0.19.10 - Broken Access Control ≤ 2.0.19.10 Fixed in 2.0.19.11 CVE-2024-50425 Patchstack
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.4.7 CVE-2024-9864 Wordfence
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed ≤ 4.0.4.7 CVE-2024-9865 Wordfence
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
6.5 Medium Booking.com Banner Creator Plugin bookingcom-banner-creator Cross-Site Scripting ≤ 1.4.6 CVE-2024-49265 Patchstack
5.9 Medium Multipurpose Ticket Booking Manager Plugin bus-booking-manager Cross-Site Scripting ≤ 4.2.2 Fixed in 4.2.3 CVE-2024-44037 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 10.9 Fixed in 10.9.1 CVE-2024-47316 Patchstack
4.4 Medium WP Booking Calendar Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 10.6 CVE-2024-9306 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
5.9 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Cross-Site Scripting ≤ 5.3.5 Fixed in 5.3.6 CVE-2024-43985 Patchstack
6.1 Medium WP Booking System – Booking Calendar Plugin wp-booking-system Cross-Site Scripting Booking Calendar <= 2.0.19.8 - Reflected Cross-Site Scripting No login needed ≤ 2.0.19.8 CVE-2024-8797 Wordfence
6.1 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.10 CVE-2024-8663 Wordfence
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
6.1 Medium WP Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 10.5 CVE-2024-8274 Wordfence
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack
6.1 Medium OTA Sync Booking Engine Widget Plugin ota-sync-booking-engine-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2024-7647 Wordfence
4.7 Medium Salon booking system Plugin salon-booking-system Open Redirect No login needed ≤ 10.8.1 Fixed in 10.9 CVE-2024-43280 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only