VulnSea

wpdevelop has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.1 (medium). Most affected products: Booking Calendar (3), booking (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
4 prev 0

Products

  • Booking Calendar 3
  • booking 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

wpdevelop vulnerabilities

CVEs affecting wpdevelop, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-93655Medium· 6.1
today

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This ma…

Sunlitwpdevelop · Booking Calendarvia NVD
CVE-2026-92619High· 7.2
4d ago

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function …

Twilightwpdevelop · Booking CalendarEPSS 0.37%via NVD
CVE-2026-92561Medium· 6.1
4d ago

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it …

Sunlitwpdevelop · Booking CalendarEPSS 0.23%via NVD
CVE-2026-74002Medium· 5.3
5d ago

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Sunlitwpdevelop · bookingEPSS 0.21%via NVD
wpdevelop vulnerabilities (CVEs) · VulnSea