2026 CVE Vulnerabilities

57,013 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1382MEDIUM6.4The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode...
CVE-2026-15155HIGH8.8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authent...
CVE-2026-15010MEDIUM6.4The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6...
CVE-2026-12994MEDIUM5.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-12738MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12126MEDIUM6.4The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-12103MEDIUM4.3The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi...
CVE-2026-11901MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version...
CVE-2026-11898MEDIUM4.4The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-11591MEDIUM4.4The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a...
CVE-2026-10865MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2026-10041MEDIUM4.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2026-7655HIGH8.1The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl...
CVE-2026-13378HIGH7.2The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac...
CVE-2026-9738MEDIUM4.4The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten...
CVE-2026-7620MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2026-7559MEDIUM4.3The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc...
CVE-2026-6804MEDIUM5.3The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions ...
CVE-2026-6803MEDIUM5.3The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions...
CVE-2026-3576HIGH7.2The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ...
CVE-2026-3552MEDIUM4.3The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi...
CVE-2026-2354HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio...
CVE-2026-1832MEDIUM4.3The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cac...
CVE-2026-15335HIGH7.5The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ...
CVE-2026-15097MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now