WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 401–450 of 474 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium myCred – Loyalty Points and Rewards Plugin mycred Cross-Site Scripting Loyalty Points and Rewards plugin <= 2.7.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode ≤ 2.7.5.2 CVE-2024-11201 Wordfence
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
7.2 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.2.15 CVE-2024-9504 Wordfence
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
7.3 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin gamipress Arbitrary Shortcode Execution The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings No login needed ≤ 7.1.5 CVE-2024-11036 Wordfence
7.1 High Appointmind Plugin appointmind Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.0 Fixed in 4.1.0 CVE-2024-51679 Patchstack
6.5 Medium Gmap Point List Plugin gmap-point-list Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.2 CVE-2024-51594 Patchstack
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
4.3 Medium UPS Live Rates and Access Points Plugin flexible-shipping-ups Broken Access Control Missing Authorization to Plugin API key reset ≤ 2.3.12 CVE-2024-9109 Wordfence
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
7.5 High Point Maker Plugin point-maker Local File Inclusion ≤ 0.1.4 Fixed in 0.1.5 CVE-2024-49317 Patchstack
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
9.8 Critical LatePoint Plugin Authentication Bypass No login needed ≤ 5.0.12 CVE-2024-8943 Wordfence
9.8 Critical LatePoint Plugin SQL Injection Unauthenticated Arbitrary User Password Change via SQL Injection No login needed ≤ 5.0.11 CVE-2024-8911 Wordfence
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
6.5 Medium LatePoint Plugin Cross-Site Scripting ≤ 4.9.91 CVE-2024-43992 Patchstack
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection Multiple Unauthenticated SQLi No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6924 WPScan
8.8 High Pinpoint Booking System Plugin booking-system SQL Injection Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection ≤ 2.9.9.5.0 CVE-2024-7112 Wordfence
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
5.3 Medium LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… Plugin ladipage Broken Access Control Missing Authorization via init_endpoint No login needed ≤ 4.3 CVE-2023-4730 Wordfence
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
9.8 Critical Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking Authentication Bypass BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover No login needed 1.1.6 – 1.1.7 CVE-2024-7350 Wordfence
5.4 Medium Pinpoint Booking System Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.9.9.4.8 Fixed in 2.9.9.4.8 CVE-2024-3636 WPScan
6.5 Medium SuperSaaS – online appointment scheduling Plugin supersaas-appointment-scheduling Cross-Site Scripting online appointment scheduling plugin <= 2.1.9 - Cross Site Scripting (XSS) ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-37460 Patchstack
7.1 High Counterpoint Theme counterpoint Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 CVE-2024-37559 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
8.8 High BookingPress Appointment Booking Plugin bookingpress-appointment-booking Path Traversal Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation ≤ 1.1.5 CVE-2024-6467 Wordfence
8.8 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Broken Access Control Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload ≤ 1.1.5 CVE-2024-6660 Wordfence
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
6.5 Medium Bookster Plugin bookster Broken Access Control Unauthenticated Appointment Status Update ≤ 1.1.0 CVE-2024-5071 WPScan
7.2 High Appointment Booking and Online Scheduling Plugin meeting-scheduler-by-vcita Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5791 Wordfence
6.1 Medium Appointment Booking and Online Scheduling Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5859 Wordfence
5.4 Medium Wheel of Life: Coaching and Assessment Tool for Life Coach Plugin wheel-of-life Broken Access Control Missing Authorization on Several AJAX Endpoints ≤ 1.1.7 CVE-2024-3627 Wordfence
9.1 Critical LatePoint Plugin Broken Access Control Missing Authorization and Sensitive Information Exposure via IDOR No login needed ≤ 4.9.9 CVE-2024-2472 Wordfence
7.3 High Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin timetics Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 1.0.21 CVE-2024-1094 Wordfence
6.5 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Appointment Duration Manipulation No login needed ≤ 1.0.82 Fixed in 1.0.83 CVE-2024-34799 Patchstack
6.4 Medium WordPress Online Booking and Scheduling Plugin – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 23.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile Parameter ≤ 23.2 CVE-2024-5584 Wordfence
6.5 Medium Pinpoint Booking System Plugin booking-system Other Parameter Tampering No login needed ≤ 2.9.9.3.4 Fixed in 2.9.9.3.5 CVE-2023-38520 Patchstack
3.7 Low Booking calendar, Appointment Booking System Plugin booking-calendar Other Bypass No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24373 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Authentication Bypass Captcha Bypass No login needed ≤ 1.4.56 Fixed in 1.4.57 CVE-2024-32720 Patchstack
7.7 High Bookly Plugin bookly-responsive-appointment-booking-tool Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 21.7.1 Fixed in 21.8 CVE-2023-26526 Patchstack
6.4 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7.14 CVE-2024-4288 Wordfence
8.2 High BookingPress Plugin bookingpress-appointment-booking Price Manipulation Booking Price Manipulation No login needed ≤ 1.0.74 Fixed in 1.0.75 CVE-2023-51405 Patchstack
4.4 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Server-Side Request Forgery ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32454 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only