2026 CVE Vulnerabilities
67,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3617 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' short... |
| CVE-2026-3570 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.... |
| CVE-2026-3554 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh... |
| CVE-2026-3546 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2026-3506 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-3478 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,... |
| CVE-2026-3460 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to... |
| CVE-2026-3354 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve... |
| CVE-2026-3353 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al... |
| CVE-2026-3347 | MEDIUM | 5.5 | 0.3% | Mar 21, 2026 | The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me... |
| CVE-2026-3335 | MEDIUM | 5.3 | 0.4% | Mar 21, 2026 | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th... |
| CVE-2026-3334 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '... |
| CVE-2026-3333 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ... |
| CVE-2026-3332 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2026-3331 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i... |
| CVE-2026-3003 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame... |
| CVE-2026-2941 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-2837 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in... |
| CVE-2026-2723 | MEDIUM | 6.1 | 0.1% | Mar 21, 2026 | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2026-2720 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ... |
| CVE-2026-2503 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i... |
| CVE-2026-2501 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ... |
| CVE-2026-2496 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso... |
| CVE-2026-2468 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,... |
| CVE-2026-2440 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now