2026 CVE Vulnerabilities
43,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11898 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-11591 | MEDIUM | 4.4 | 0.3% | Jul 11, 2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2026-10865 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2026-10041 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... |
| CVE-2026-9738 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten... |
| CVE-2026-7620 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2026-7559 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2026-6804 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions ... |
| CVE-2026-6803 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions... |
| CVE-2026-3552 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi... |
| CVE-2026-1832 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cac... |
| CVE-2026-15097 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ... |
| CVE-2026-15096 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field... |
| CVE-2026-13250 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3.... |
| CVE-2026-13116 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ... |
| CVE-2026-12141 | MEDIUM | 4.9 | 0.2% | Jul 11, 2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C... |
| CVE-2026-8678 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th... |
| CVE-2026-7544 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2026-5743 | MEDIUM | 6.4 | 0.3% | Jul 11, 2026 | The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribut... |
| CVE-2026-3367 | MEDIUM | 4.4 | 0.3% | Jul 11, 2026 | The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I... |
| CVE-2026-15073 | MEDIUM | 6.5 | 0.2% | Jul 11, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-15072 | MEDIUM | 6.5 | 0.3% | Jul 11, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-13262 | MEDIUM | 6.5 | 0.4% | Jul 11, 2026 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generi... |
| CVE-2026-12426 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2026-10628 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now