WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 301–350 of 471 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters No login needed ≤ 1.6.9.9 CVE-2025-12166 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Broken Access Control Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions No login needed ≤ 1.2.38 CVE-2025-14720 Wordfence
6.5 Medium Appointment Booking and Scheduling Calendar Plugin – WP Timetics Plugin timetics Broken Access Control WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification No login needed ≤ 1.0.36 CVE-2025-5919 Wordfence
4.3 Medium GamiPress – Gamification plugin to reward points, achievements, badges & ranks in Plugin Broken Access Control Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 7.6.1 CVE-2025-13812 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.5 CVE-2025-11723 Wordfence
4.3 Medium Appointify Plugin appointify Cross-Site Request Forgery No login needed ≤ 1.0.8 CVE-2025-59130 Patchstack
7.6 High Appointify Plugin appointify SQL Injection ≤ 1.0.8 CVE-2025-59129 Patchstack
5.3 Medium Wappointment Plugin wappointment Broken Access Control No login needed ≤ 2.7.6 CVE-2025-68575 Patchstack
4.3 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program Plugin mycred Broken Access Control Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 - Missing Authorization to Sensitive Information Exposure ≤ 2.9.7.1 CVE-2025-12361 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
4.3 Medium Converter for Media Plugin webp-converter-for-media Broken Access Control Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint ≤ 6.3.2 CVE-2025-13750 Wordfence
5.3 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program Plugin mycred Broken Access Control Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 - Missing Authorization to Unauthenticated Withdrawal Request Approval No login needed ≤ 2.9.7 CVE-2025-12362 Wordfence
5.3 Medium Guest Support Plugin guest-support Information Disclosure Unauthenticated User Email Disclosure in guest_support_handler AJAX Endpoint No login needed ≤ 1.2.3 CVE-2025-13660 Wordfence
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-67581 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.30 Fixed in 3.2.31 CVE-2025-67574 Patchstack
6.5 Medium Wappointment Plugin wappointment Cross-Site Scripting ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-67551 Patchstack
5.3 Medium Wp Social Login and Register Social Counter Plugin wp-social Broken Access Control Missing Authorization in Cache REST Endpoints to Social Counter Tampering No login needed ≤ 3.1.3 CVE-2025-13620 Wordfence
9.8 Critical CRM Memberships Plugin crm-memberships Broken Access Control Missing Authorization to Privilege Escalation via Unauthenticated Password Reset in 'ntzcrm_changepassword' AJAX Endpoint No login needed ≤ 2.6 CVE-2025-13313 Wordfence
4.3 Medium Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution Plugin fluent-booking Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management ≤ 1.9.11 CVE-2025-13756 Wordfence
5.3 Medium Zigaform Plugin zigaform-calculator-cost-estimation-form-builder-lite Information Disclosure Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint No login needed ≤ 7.6.5 CVE-2025-13696 Wordfence
4.9 Medium Bookme Plugin bookme-free-appointment-booking-system SQL Injection Authenticated (Admin+) SQL Injection via 'filter[status]' Parameter ≤ 4.2 CVE-2025-13385 Wordfence
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter No login needed ≤ 1.3.96 CVE-2025-13317 Wordfence
8.8 High Vitepos – Point of Sale (POS) for WooCommerce Plugin vitepos-lite Arbitrary File Upload Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution ≤ 3.3.0 CVE-2025-13156 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
7.5 High Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 1.2.35 - Unauthenticated SQL Injection via search No login needed ≤ 1.2.35 CVE-2025-12482 Wordfence
4.3 Medium WooCommerce Ultimate Points And Rewards Plugin woocommerce-ultimate-points-and-rewards Information Disclosure Sensitive Data Exposure ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-64267 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack
7.5 High Booking Calendar | Appointment Booking | Bookit Plugin bookit Broken Access Control Missing Authorization to Unauthenticated Stripe Connection No login needed ≤ 2.5.0 CVE-2025-12633 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed ≤ 1.1.27 CVE-2025-12788 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed ≤ 1.1.27 CVE-2025-12787 Wordfence
6.5 Medium Easy Appointments Plugin easy-appointments Content Injection No login needed ≤ 3.12.14 Fixed in 3.12.14.1 CVE-2025-49398 Patchstack
6.8 Medium Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint ≤ 5.2.4 CVE-2025-12136 Wordfence
7.1 High gAppointments Plugin gappointments Cross-Site Scripting No login needed ≤ 1.14.1 CVE-2025-49951 Patchstack
9.8 Critical Appointments Plugin appointments PHP Object Injection Unauthenticated PHP Object Injection No login needed < 2.2.2 Fixed in 2.2.2 CVE-2017-20206 Wordfence
8.8 High LatePoint Plugin latepoint Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover via change_password() Function No login needed ≤ 5.1.94 CVE-2025-7052 Wordfence
8.2 High LatePoint Plugin latepoint Authentication Bypass Unauthenticated Authentication Bypass via load_step Function No login needed ≤ 5.1.94 CVE-2025-7038 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.1.94 CVE-2025-6941 Wordfence
5.5 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.94 CVE-2025-6815 Wordfence
4.3 Medium Advanced Appointment Booking & Scheduling Plugin advanced-appointment-booking-scheduling Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-57978 Patchstack
6.4 Medium Appointmind Plugin appointmind Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2025-9851 Wordfence
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
9.8 Critical Latepoint Plugin Local File Inclusion Unauthenticated LFI No login needed < 5.1.94 Fixed in 5.1.94 CVE-2025-6715 WPScan
6.5 Medium Omnishop Plugin omnishop Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary User Deletion via /users/delete REST Endpoint No login needed ≤ 1.0.9 CVE-2025-6214 Wordfence
5.3 Medium Omnishop Plugin omnishop Broken Access Control Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint No login needed ≤ 1.0.9 CVE-2025-6215 Wordfence
9.8 Critical bSecure Plugin bsecure Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint No login needed 1.3.7 – 1.7.9 CVE-2025-6187 Wordfence
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
6.4 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 1.6.8.30 CVE-2025-4667 Wordfence
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
4.3 Medium CubePoints Plugin cubepoints Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-28952 Patchstack
9.8 Critical Profitori Plugin profitori Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via stocktend_object Endpoint No login needed 2.0.6.0 – 2.1.1.3 CVE-2025-4631 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only