2026 CVE Vulnerabilities

45,590 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18786HIGH8.8The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and ...
CVE-2026-18666MEDIUM4.3The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-18470HIGH7.5The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a...
CVE-2026-18469HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se...
CVE-2026-18468HIGH8.1The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc...
CVE-2026-18200MEDIUM4.3The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user ...
CVE-2026-18030HIGH8.1The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password...
CVE-2026-17542HIGH7.5The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto...
CVE-2026-17541HIGH7.5The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin...
CVE-2026-17540HIGH8.8The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any au...
CVE-2026-17023MEDIUM4.8The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s...
CVE-2026-17022HIGH7.5The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before...
CVE-2026-17021MEDIUM5.3The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif...
CVE-2026-17020MEDIUM4.3The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle...
CVE-2026-17019MEDIUM6.1The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and...
CVE-2026-17018MEDIUM4.9The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric...
CVE-2026-17016LOW3.7The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun...
CVE-2026-17012MEDIUM5.3The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the Pa...
CVE-2026-17010MEDIUM5.4The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o...
CVE-2026-16985HIGH8.8The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ...
CVE-2026-16949MEDIUM5.8The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ...
CVE-2026-16299CRITICAL9.8The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u...
CVE-2026-16298CRITICAL9.8The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthen...
CVE-2026-16257HIGH8.2The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh...
CVE-2026-15238MEDIUM5.4The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now