WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
7.3 High TheBooking Plugin thebooking Broken Access Control No login needed ≤ 1.4.4 CVE-2025-52801 Patchstack
4.3 Medium CBX Restaurant Booking Plugin Cross-Site Request Forgery Plugin Reset via CSRF No login needed ≤ 1.2.1 CVE-2025-7965 WPScan
9.8 Critical Service Finder Bookings Plugin Authentication Bypass Authentication Bypass via User Switch Cookie No login needed ≤ 6.0 CVE-2025-5947 Wordfence
8.8 High Hydra Booking Plugin hydra-booking Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function 1.1.0 – 1.1.18 CVE-2025-7689 Wordfence
7.1 High Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2025-52787 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Cross-Site Request Forgery No login needed ≤ 5.1.20 Fixed in 5.1.21 CVE-2025-54036 Patchstack
6.5 Medium WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 6.7.16 CVE-2025-3780 Wordfence
9.8 Critical Service Finder Booking Plugin sf-booking Privilege Escalation No login needed ≤ 6.1 CVE-2025-23970 Patchstack
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
7.5 High Booking X Plugin booking-x Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via export_now() Function No login needed 1.0 – 1.1.2 CVE-2025-6814 Wordfence
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.7 Fixed in 3.8 CVE-2025-53259 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-25173 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
5.9 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-30637 Patchstack
4.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Request Forgery No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2025-49332 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49323 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2025-47585 Patchstack
5.3 Medium Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking Plugin easync-booking Broken Access Control eaSYNC Booking <= 1.3.21 - Insecure Direct Object Reference to Sensitive Information Exposure No login needed ≤ 1.3.21 CVE-2025-4691 Wordfence
9.3 Critical Bus Ticket Booking with Seat Reservation for WooCommerce Plugin scw-bus-seat-reservation SQL Injection No login needed ≤ 1.7 CVE-2025-31397 Patchstack
8.5 High FAT Services Booking Plugin fat-services-booking SQL Injection ≤ 5.6 CVE-2025-39355 Patchstack
4.3 Medium Bellevue Theme bellevuex Broken Access Control ≤ 4.2.2 CVE-2025-39398 Patchstack
4.3 Medium Car Park Booking System Plugin car-park-booking-system-for-wordpress Broken Access Control ≤ 2.6 CVE-2025-39376 Patchstack
5.4 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery CSRF to Arbitrary Content Deletion No login needed ≤ 10.16 Fixed in 10.17 CVE-2025-47583 Patchstack
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode ≤ 10.11.1 CVE-2025-4669 Wordfence
4.3 Medium Salon Booking Pro Plugin salon-booking-plugin-pro-cc Broken Access Control ≤ 10.10.2 CVE-2025-32295 Patchstack
4.3 Medium QuickCal - Appointment Booking Calendar Plugin quickcal Information Disclosure Sensitive Data Exposure ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32299 Patchstack
8.8 High QuickCal - Appointment Booking Calendar Plugin quickcal Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0.15 Fixed in 1.0.16 CVE-2025-32310 Patchstack
7.5 High FAT Services Booking Plugin fat-services-booking Local File Inclusion ≤ 5.5 CVE-2025-47693 Patchstack
6.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update 3.4.9 – < 3.5.0 Fixed in 3.5.0 CVE-2024-4665 WPScan
4.8 Medium Salon Booking System Plugin salon-booking-system Cross-Site Scripting Admin+ Stored XSS < 1.9.4 Fixed in 1.9.4 CVE-2024-9882 WPScan
6.5 Medium Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking Plugin Cross-Site Request Forgery eaSYNC Booking < 1.3.15 - Subscriber+ PayPal Settings Update No login needed < 1.3.15 Fixed in 1.3.15 CVE-2024-9450 WPScan
4.8 Medium VikBooking Plugin Cross-Site Scripting Admin+ Stored XSS < 1.7.2 Fixed in 1.7.2 CVE-2024-13616 WPScan
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-47543 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.6 Fixed in 3.7 CVE-2025-47498 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.29 Fixed in 2.0.30 CVE-2025-47489 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.1.9 Fixed in 2.2.0 CVE-2025-47448 Patchstack
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Reservation & Post Deletion ≤ 2.4.4 CVE-2025-1326 Wordfence
4.3 Medium Homey - Booking and Rentals Theme Broken Access Control Booking and Rentals WordPress Theme <= 2.4.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 2.4.4 CVE-2025-1327 Wordfence
9.8 Critical Service Finder Bookings Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' No login needed ≤ 5.1 CVE-2025-2470 Wordfence
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39390 Patchstack
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46247 Patchstack
8.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.3.92 Fixed in 1.3.93 CVE-2025-46241 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.1.20 CVE-2025-27345 Patchstack
7.1 High Course Booking System Plugin course-booking-system Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-32508 Patchstack
8.8 High TuriTop Booking System Plugin turitop-booking-system PHP Object Injection ≤ 1.0.10 CVE-2025-32571 Patchstack
8.1 High Hotel Booking Plugin nd-booking Local File Inclusion No login needed ≤ 3.6 Fixed in 3.7 CVE-2025-39526 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-39457 Patchstack
7.6 High BMA Lite Plugin bma-lite-appointment-booking-and-scheduling SQL Injection ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-39518 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only