2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18943MEDIUM6.5The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow...
CVE-2026-18789HIGH7.5The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ...
CVE-2026-18474HIGH8.6The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18391CRITICAL9.8The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366CRITICAL9.8The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230HIGH8.1The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057HIGH8.1The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...
CVE-2026-18049HIGH7.5The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-18048HIGH7.5The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f...
CVE-2026-18046MEDIUM4.3The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-18035MEDIUM5.3The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo...
CVE-2026-17013MEDIUM6.1The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it...
CVE-2026-16977HIGH8.1The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ...
CVE-2026-16737MEDIUM5.3The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca...
CVE-2026-16538CRITICAL9.1The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top...
CVE-2026-16294HIGH7.1The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode...
CVE-2026-16253HIGH7.5The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto...
CVE-2026-16066MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it ...
CVE-2026-16051CRITICAL9.8The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re...
CVE-2026-15388MEDIUM4.3The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-15249MEDIUM5.4The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i...
CVE-2026-15039CRITICAL9.8The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all...
CVE-2026-14925HIGH7.5The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo...
CVE-2026-14859MEDIUM4.3The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...
CVE-2026-14858MEDIUM4.3The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now