2026 CVE Vulnerabilities

43,946 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11898MEDIUM4.4The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-11591MEDIUM4.4The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a...
CVE-2026-10865MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2026-10041MEDIUM4.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2026-9738MEDIUM4.4The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten...
CVE-2026-7620MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2026-7559MEDIUM4.3The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc...
CVE-2026-6804MEDIUM5.3The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions ...
CVE-2026-6803MEDIUM5.3The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions...
CVE-2026-3552MEDIUM4.3The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi...
CVE-2026-1832MEDIUM4.3The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cac...
CVE-2026-15097MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ...
CVE-2026-15096MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field...
CVE-2026-13250MEDIUM5.3The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3....
CVE-2026-13116MEDIUM4.3The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ...
CVE-2026-12141MEDIUM4.9The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C...
CVE-2026-8678MEDIUM4.3The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th...
CVE-2026-7544MEDIUM4.3The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i...
CVE-2026-5743MEDIUM6.4The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribut...
CVE-2026-3367MEDIUM4.4The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I...
CVE-2026-15073MEDIUM6.5The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-15072MEDIUM6.5The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-13262MEDIUM6.5The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generi...
CVE-2026-12426MEDIUM5.3The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2026-10628MEDIUM4.3The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now