VulnSea

WPdevelop has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. Most affected products: Booking Calendar (3), booking (2).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • Booking Calendar 3
  • booking 2
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

WPdevelop vulnerabilities

CVEs affecting WPdevelop, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-39601Low· 3.7
today

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.

▾ SunlitWPdevelop · bookingvia NVD
CVE-2026-93655Medium· 6.1
1w ago

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This ma…

▾ Sunlitwpdevelop · Booking CalendarEPSS 0.37%via NVD
CVE-2026-92619High· 7.2
2w ago

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function …

▾ Twilightwpdevelop · Booking CalendarEPSS 0.66%via NVD
CVE-2026-92561Medium· 6.1
2w ago

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it …

▾ Sunlitwpdevelop · Booking CalendarEPSS 0.41%via NVD
CVE-2026-74002Medium· 5.3
2w ago

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

▾ Sunlitwpdevelop · bookingEPSS 0.29%via NVD
WPdevelop vulnerabilities (CVEs) · VulnSea