2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91024 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iC... |
| CVE-2026-90985 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection ... |
| CVE-2026-90951 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment action... |
| CVE-2026-89331 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token... |
| CVE-2026-88997 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it i... |
| CVE-2026-88929 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a produc... |
| CVE-2026-87981 | MEDIUM | 4.7 | 0.2% | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX acti... |
| CVE-2026-87979 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch... |
| CVE-2026-87074 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who cre... |
| CVE-2026-87069 | LOW | 3.1 | 0.2% | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before ru... |
| CVE-2026-86842 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flip... |
| CVE-2026-86785 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its RES... |
| CVE-2026-86783 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility chec... |
| CVE-2026-86608 | HIGH | 8.2 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor ... |
| CVE-2026-86603 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, all... |
| CVE-2026-86602 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, all... |
| CVE-2026-85006 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets... |
| CVE-2026-84743 | LOW | 3.8 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R... |
| CVE-2026-84742 | LOW | 2.7 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before crea... |
| CVE-2026-84741 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding the... |
| CVE-2026-84168 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthen... |
| CVE-2026-84150 | MEDIUM | 5.4 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify ... |
| CVE-2026-84098 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properl... |
| CVE-2026-84046 | MEDIUM | 5 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validat... |
| CVE-2026-84027 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now