2026 CVE Vulnerabilities
67,706 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84909 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2026-79713 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-... |
| CVE-2026-75017 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu... |
| CVE-2026-75016 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client... |
| CVE-2026-18317 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a... |
| CVE-2026-17576 | MEDIUM | 6.5 | — | Sep 18, 2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,... |
| CVE-2026-12106 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, ... |
| CVE-2026-93485 | HIGH | 7.1 | 0.2% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre... |
| CVE-2026-90984 | MEDIUM | 5.8 | — | Sep 18, 2026 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch... |
| CVE-2026-90978 | HIGH | 7.1 | — | Sep 18, 2026 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc... |
| CVE-2026-89008 | LOW | 2.7 | — | Sep 18, 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o... |
| CVE-2026-89007 | LOW | 2.7 | — | Sep 18, 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o... |
| CVE-2026-88993 | MEDIUM | 6.8 | — | Sep 18, 2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it... |
| CVE-2026-88844 | LOW | 2.7 | — | Sep 18, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c... |
| CVE-2026-88825 | HIGH | 8.8 | — | Sep 18, 2026 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin... |
| CVE-2026-88798 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using... |
| CVE-2026-87966 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth... |
| CVE-2026-87965 | MEDIUM | 4.8 | — | Sep 18, 2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi... |
| CVE-2026-87775 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87774 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87771 | HIGH | 8.6 | — | Sep 18, 2026 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them... |
| CVE-2026-87770 | HIGH | 8.6 | — | Sep 18, 2026 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ... |
| CVE-2026-87767 | HIGH | 8.6 | — | Sep 18, 2026 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef... |
| CVE-2026-85350 | MEDIUM | 5.3 | — | Sep 18, 2026 | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought ... |
| CVE-2026-85127 | HIGH | 8.8 | — | Sep 18, 2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now