2026 CVE Vulnerabilities

68,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-89007LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o...
CVE-2026-88993MEDIUM6.8The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it...
CVE-2026-88844LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c...
CVE-2026-88825HIGH8.8The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin...
CVE-2026-88798MEDIUM5.3The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using...
CVE-2026-87966MEDIUM5.3The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth...
CVE-2026-87965MEDIUM4.8The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi...
CVE-2026-87775HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87774HIGH8.6The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ...
CVE-2026-87771HIGH8.6The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them...
CVE-2026-87770HIGH8.6The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ...
CVE-2026-87767HIGH8.6The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef...
CVE-2026-85350MEDIUM5.3The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought ...
CVE-2026-85127HIGH8.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic...
CVE-2026-85123MEDIUM5.3The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor...
CVE-2026-85122HIGH8.8The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor...
CVE-2026-85009MEDIUM6.5The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on ...
CVE-2026-84904LOW3.8The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a gro...
CVE-2026-84903LOW2.7The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password...
CVE-2026-84902MEDIUM6.8The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when...
CVE-2026-84738CRITICAL9.1The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import f...
CVE-2026-81810HIGH7.2The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of...
CVE-2026-81340LOW3.8The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability...
CVE-2026-18912HIGH7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo...
CVE-2026-18911HIGH7.5ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now