2026 CVE Vulnerabilities

68,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-90976MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco...
CVE-2026-89413HIGH8.1The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1....
CVE-2026-89330MEDIUM6.1The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for ...
CVE-2026-89278MEDIUM5.3The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v...
CVE-2026-89138MEDIUM4.3The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1....
CVE-2026-88994MEDIUM6.6The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a ...
CVE-2026-86800MEDIUM5.3The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before ...
CVE-2026-86796MEDIUM5.3The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befo...
CVE-2026-84909MEDIUM6.4The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-79713MEDIUM6.5The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-...
CVE-2026-75017MEDIUM4.3The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2026-75016MEDIUM6.4The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client...
CVE-2026-18317MEDIUM4.3The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a...
CVE-2026-17576MEDIUM6.5The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,...
CVE-2026-12106MEDIUM6.4The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, ...
CVE-2026-93485HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre...
CVE-2026-90984MEDIUM5.8The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch...
CVE-2026-90978HIGH7.1The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc...
CVE-2026-89008LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o...
CVE-2026-89007LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o...
CVE-2026-88993MEDIUM6.8The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it...
CVE-2026-88844LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c...
CVE-2026-88825HIGH8.8The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin...
CVE-2026-88798MEDIUM5.3The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using...
CVE-2026-87966MEDIUM5.3The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now