2026 CVE Vulnerabilities
67,282 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15098 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortc... |
| CVE-2026-13770 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vul... |
| CVE-2026-13200 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, ... |
| CVE-2026-13191 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up t... |
| CVE-2026-12402 | MEDIUM | 4.4 | 0.2% | Sep 19, 2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' S... |
| CVE-2026-11899 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorizat... |
| CVE-2026-11608 | MEDIUM | 6.1 | 0.3% | Sep 19, 2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param... |
| CVE-2026-92435 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required ... |
| CVE-2026-92430 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the aut... |
| CVE-2026-92425 | MEDIUM | 5.5 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-leve... |
| CVE-2026-92421 | MEDIUM | 4.7 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the hos... |
| CVE-2026-92420 | LOW | 3.8 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booki... |
| CVE-2026-92404 | HIGH | 7.5 | 0.3% | Sep 19, 2026 | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowi... |
| CVE-2026-92403 | LOW | 3.7 | 0.2% | Sep 19, 2026 | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresp... |
| CVE-2026-92099 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied que... |
| CVE-2026-91847 | MEDIUM | 4.8 | 0.1% | Sep 19, 2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester ow... |
| CVE-2026-88926 | HIGH | 8.6 | 0.3% | Sep 19, 2026 | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of it... |
| CVE-2026-88824 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe... |
| CVE-2026-86814 | HIGH | 8.1 | 0.2% | Sep 19, 2026 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an e... |
| CVE-2026-86591 | CRITICAL | 9.8 | 0.4% | Sep 19, 2026 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowi... |
| CVE-2026-85680 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef... |
| CVE-2026-85574 | HIGH | 8 | 0.2% | Sep 19, 2026 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf... |
| CVE-2026-84750 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo... |
| CVE-2026-76790 | HIGH | 7.1 | 0.1% | Sep 19, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ... |
| CVE-2026-76554 | HIGH | 7.2 | 0.3% | Sep 19, 2026 | The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now