2026 CVE Vulnerabilities

67,282 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15098MEDIUM6.4The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortc...
CVE-2026-13770MEDIUM6.4The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vul...
CVE-2026-13200MEDIUM6.5The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, ...
CVE-2026-13191MEDIUM6.5The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up t...
CVE-2026-12402MEDIUM4.4The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' S...
CVE-2026-11899MEDIUM4.3The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorizat...
CVE-2026-11608MEDIUM6.1The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param...
CVE-2026-92435MEDIUM5.3The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required ...
CVE-2026-92430MEDIUM5.3The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the aut...
CVE-2026-92425MEDIUM5.5The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-leve...
CVE-2026-92421MEDIUM4.7The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the hos...
CVE-2026-92420LOW3.8The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booki...
CVE-2026-92404HIGH7.5The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowi...
CVE-2026-92403LOW3.7The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresp...
CVE-2026-92099MEDIUM6.5The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied que...
CVE-2026-91847MEDIUM4.8The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester ow...
CVE-2026-88926HIGH8.6The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of it...
CVE-2026-88824HIGH8.8The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe...
CVE-2026-86814HIGH8.1The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an e...
CVE-2026-86591CRITICAL9.8The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowi...
CVE-2026-85680HIGH8.8The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef...
CVE-2026-85574HIGH8The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf...
CVE-2026-84750MEDIUM6.5The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo...
CVE-2026-76790HIGH7.1The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ...
CVE-2026-76554HIGH7.2The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now