2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-91024MEDIUM6.8The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iC...
CVE-2026-90985MEDIUM5.3The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection ...
CVE-2026-90951LOW3.7The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment action...
CVE-2026-89331MEDIUM5.3The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token...
CVE-2026-88997MEDIUM6.8The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it i...
CVE-2026-88929MEDIUM5.3The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a produc...
CVE-2026-87981MEDIUM4.7The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX acti...
CVE-2026-87979MEDIUM5.3The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch...
CVE-2026-87074LOW3.7The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who cre...
CVE-2026-87069LOW3.1The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before ru...
CVE-2026-86842MEDIUM6.8The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flip...
CVE-2026-86785MEDIUM5.3The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its RES...
CVE-2026-86783MEDIUM5.3The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility chec...
CVE-2026-86608HIGH8.2The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor ...
CVE-2026-86603MEDIUM4.3The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, all...
CVE-2026-86602MEDIUM4.3The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, all...
CVE-2026-85006MEDIUM6.8The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets...
CVE-2026-84743LOW3.8The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R...
CVE-2026-84742LOW2.7The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before crea...
CVE-2026-84741MEDIUM5.3The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding the...
CVE-2026-84168MEDIUM5.3The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthen...
CVE-2026-84150MEDIUM5.4The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify ...
CVE-2026-84098MEDIUM6.5The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properl...
CVE-2026-84046MEDIUM5The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validat...
CVE-2026-84027MEDIUM4.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now