FareHarbor for WordPress
FareHarbor for WordPress has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for FareHarbor for WordPress has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. FareHarbor for WordPress is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2023-5252FareHarbor for WordPress <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

FareHarbor for WordPress
Author
FareHarbor
Adds shortcodes that make it easy to embed FareHarbor booking calendars and buttons on your site. Learn more about the FareHarbor reservation system at fareharbor.com. Includes shortcodes for embedded calendars ([fareharbor]), embedded grids of activities ([itemgrid]), and buttons that open a booking overlay ([lightframe]). For more examples and available options, please visit https://fareharbor.com/help/setup/wordpress-plugin/.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C