2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6246MEDIUM6.4The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_r...
CVE-2026-6236MEDIUM6.4The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in al...
CVE-2026-6235CRITICAL9.8The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests'...
CVE-2026-6041MEDIUM4.4The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c...
CVE-2026-5820MEDIUM6.4The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in ...
CVE-2026-5767MEDIUM6.4The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` ...
CVE-2026-5748MEDIUM6.4The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in a...
CVE-2026-4353MEDIUM6.4The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `ci...
CVE-2026-4280MEDIUM6.5The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1....
CVE-2026-4279MEDIUM6.4The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-bu...
CVE-2026-4142MEDIUM4.4The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4140MEDIUM4.3The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a...
CVE-2026-4139MEDIUM4.3The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5....
CVE-2026-4138MEDIUM4.3The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-4133MEDIUM4.3The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and in...
CVE-2026-4132HIGH7.2The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec...
CVE-2026-4131MEDIUM6.1The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a...
CVE-2026-4128MEDIUM4.3The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up ...
CVE-2026-4126MEDIUM4.3The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2026-4125MEDIUM6.4The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in ...
CVE-2026-4121MEDIUM4.3The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1....
CVE-2026-4119CRITICAL9.1The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2....
CVE-2026-4118MEDIUM4.3The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-4117MEDIUM5.3The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is ...
CVE-2026-4090MEDIUM6.1The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now