2026 CVE Vulnerabilities

67,282 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5410MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions ...
CVE-2026-1256MEDIUM6.4The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple A...
CVE-2026-1255HIGH7.5The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2026-18346MEDIUM5.3The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This ...
CVE-2026-9855MEDIUM6.5The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all...
CVE-2026-9832MEDIUM5.3The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph...
CVE-2026-9615MEDIUM4.3The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. T...
CVE-2026-9232MEDIUM6.5The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2026-87917MEDIUM6.1The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynam...
CVE-2026-85658HIGH8.1The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-7527MEDIUM4.7The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all version...
CVE-2026-75959MEDIUM4.9The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' paramet...
CVE-2026-6295MEDIUM4.9The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and inc...
CVE-2026-5400MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values ...
CVE-2026-4792MEDIUM5.3The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due...
CVE-2026-4327HIGH8.8The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1...
CVE-2026-2422MEDIUM6.4The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pb...
CVE-2026-2278MEDIUM4.3The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2026-1984MEDIUM5.3The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a...
CVE-2026-1641MEDIUM6.5The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions ...
CVE-2026-1242MEDIUM4.3The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callb...
CVE-2026-15947MEDIUM4.3The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2026-15946MEDIUM4.3The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2026-15664HIGH7.2The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-15463MEDIUM6.1The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now