2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9014MEDIUM5.3The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-8994HIGH8.1The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0....
CVE-2026-8943MEDIUM4.3The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-8941MEDIUM4.3The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8939MEDIUM4.3The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2026-8938MEDIUM4.3The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8911MEDIUM6.1The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8903MEDIUM4.3The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al...
CVE-2026-8899MEDIUM6.4The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a...
CVE-2026-8898MEDIUM6.4The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v...
CVE-2026-8897MEDIUM6.4The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve...
CVE-2026-8894MEDIUM6.4The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod...
CVE-2026-8891MEDIUM6.4The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve...
CVE-2026-8887MEDIUM6.4The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in ver...
CVE-2026-8886MEDIUM6.4The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in ve...
CVE-2026-8884MEDIUM6.4The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attr...
CVE-2026-8877MEDIUM6.4The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shor...
CVE-2026-8875MEDIUM6.4The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'co...
CVE-2026-8873MEDIUM6.4The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ...
CVE-2026-8872MEDIUM6.4The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-s...
CVE-2026-8871MEDIUM6.4The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcod...
CVE-2026-8870MEDIUM6.4The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-8869MEDIUM6.4The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attrib...
CVE-2026-8868MEDIUM6.4The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortc...
CVE-2026-8867MEDIUM6.4The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcatego...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now