2026 CVE Vulnerabilities

67,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3617MEDIUM6.4The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' short...
CVE-2026-3570MEDIUM5.3The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2....
CVE-2026-3554MEDIUM6.4The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh...
CVE-2026-3546MEDIUM5.3The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-3506MEDIUM5.3The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-3478HIGH7.2The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,...
CVE-2026-3460MEDIUM5.3The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...
CVE-2026-3354MEDIUM4.4The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve...
CVE-2026-3353MEDIUM4.4The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al...
CVE-2026-3347MEDIUM5.5The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me...
CVE-2026-3335MEDIUM5.3The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th...
CVE-2026-3334HIGH8.8The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '...
CVE-2026-3333MEDIUM6.4The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ...
CVE-2026-3332MEDIUM4.3The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-3331MEDIUM4.3The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2026-3003HIGH7.2The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame...
CVE-2026-2941HIGH8.8The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-2837MEDIUM4.4The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in...
CVE-2026-2723MEDIUM6.1The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-2720MEDIUM6.5The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ...
CVE-2026-2503MEDIUM6.5The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i...
CVE-2026-2501MEDIUM6.4The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ...
CVE-2026-2496MEDIUM6.4The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso...
CVE-2026-2468HIGH7.5The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,...
CVE-2026-2440HIGH7.2The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now