2026 CVE Vulnerabilities

66,201 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93901HIGH7.3The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ...
CVE-2026-93747MEDIUM6.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v...
CVE-2026-93656MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-93654HIGH7.2The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-92713HIGH8.1The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due ...
CVE-2026-92609CRITICAL9.8Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticat...
CVE-2026-92608HIGH7.5Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated messa...
CVE-2026-89426HIGH8.8The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation...
CVE-2026-89406HIGH7.5The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of p...
CVE-2026-88996MEDIUM6.1The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres...
CVE-2026-84280HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elemen...
CVE-2026-19804HIGH8.8The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2026-17602MEDIUM4.9The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in a...
CVE-2026-17577MEDIUM6.1The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters i...
CVE-2026-13456HIGH7.5The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2026-13179MEDIUM6.4The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2026-12037MEDIUM5.5The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions ...
CVE-2026-97846MEDIUM6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client ...
CVE-2026-96766MEDIUM6.4The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-96039HIGH7.2The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all...
CVE-2026-94376MEDIUM6.4The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stor...
CVE-2026-93899MEDIUM6.5The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to gene...
CVE-2026-93897MEDIUM6.4The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-93477MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a...
CVE-2026-93399CRITICAL9.1The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now