2026 CVE Vulnerabilities

67,706 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-84909MEDIUM6.4The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-79713MEDIUM6.5The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-...
CVE-2026-75017MEDIUM4.3The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2026-75016MEDIUM6.4The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client...
CVE-2026-18317MEDIUM4.3The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a...
CVE-2026-17576MEDIUM6.5The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,...
CVE-2026-12106MEDIUM6.4The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, ...
CVE-2026-93485HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre...
CVE-2026-90984MEDIUM5.8The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch...
CVE-2026-90978HIGH7.1The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc...
CVE-2026-89008LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o...
CVE-2026-89007LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o...
CVE-2026-88993MEDIUM6.8The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it...
CVE-2026-88844LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c...
CVE-2026-88825HIGH8.8The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin...
CVE-2026-88798MEDIUM5.3The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using...
CVE-2026-87966MEDIUM5.3The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth...
CVE-2026-87965MEDIUM4.8The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi...
CVE-2026-87775HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87774HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87771HIGH8.6The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them...
CVE-2026-87770HIGH8.6The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ...
CVE-2026-87767HIGH8.6The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef...
CVE-2026-85350MEDIUM5.3The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought ...
CVE-2026-85127HIGH8.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now