2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8685MEDIUM6.5The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all ...
CVE-2026-8627MEDIUM6.1The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var...
CVE-2026-8626MEDIUM6.1The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version...
CVE-2026-8624MEDIUM6.1The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param...
CVE-2026-8610MEDIUM4.3The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-8424MEDIUM4.3The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8423MEDIUM4.3The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-8420MEDIUM6.1The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8419MEDIUM4.3The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-8418MEDIUM4.3The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2...
CVE-2026-8038MEDIUM6.4The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu...
CVE-2026-7472MEDIUM4.9The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet...
CVE-2026-7467HIGH8.8The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-7462MEDIUM6.1The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all...
CVE-2026-7284CRITICAL9.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation ...
CVE-2026-6555CRITICAL9.8The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, ...
CVE-2026-6549MEDIUM6.4The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute ...
CVE-2026-6456HIGH8.8The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2026-6452MEDIUM4.3The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-6404MEDIUM4.4The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2026-6401MEDIUM4.3The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1....
CVE-2026-6400MEDIUM4.3The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2026-6399MEDIUM4.4The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1....
CVE-2026-6397MEDIUM6.4The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete...
CVE-2026-6395MEDIUM6.1The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now