FareHarbor for WordPress

FareHarbor for WordPress has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for FareHarbor for WordPress has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. FareHarbor for WordPress is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all FareHarbor for WordPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2023-5252

FareHarbor for WordPress <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

2 records
FareHarbor for WordPress banner
Latestv3.6.15

FareHarbor for WordPress

FareHarbor

Author

FareHarbor

4.3(4)
86/100
Last Updated
2026-08-04 (1mo ago)
Active Installs
9,000+
Downloads
154,125
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2014-08-15 (12y ago)

Adds shortcodes that make it easy to embed FareHarbor booking calendars and buttons on your site. Learn more about the FareHarbor reservation system at fareharbor.com. Includes shortcodes for embedded calendars ([fareharbor]), embedded grids of activities ([itemgrid]), and buttons that open a booking overlay ([lightframe]). For more examples and available options, please visit https://fareharbor.com/help/setup/wordpress-plugin/.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C