2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16067MEDIUM5.3The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the ...
CVE-2026-15734CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att...
CVE-2026-15733CRITICAL9.8A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio...
CVE-2026-15732CRITICAL9.8A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona...
CVE-2026-15256MEDIUM4.8The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate ...
CVE-2026-15208MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p...
CVE-2026-15152MEDIUM5.3The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment ...
CVE-2026-15149MEDIUM5.3The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar...
CVE-2026-15147MEDIUM5.3The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen...
CVE-2026-14936MEDIUM5.3The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s...
CVE-2026-14842MEDIUM5.3The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b...
CVE-2026-14831MEDIUM5.3The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat...
CVE-2026-14812CRITICAL10The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator ...
CVE-2026-14306MEDIUM4.3The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co...
CVE-2026-14225LOW2.7The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re...
CVE-2026-13399HIGH7.5The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a...
CVE-2026-13342MEDIUM5.3The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base...
CVE-2026-12901MEDIUM5.9The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, ...
CVE-2026-12584HIGH7.5The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco...
CVE-2026-12501MEDIUM5.3The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent...
CVE-2026-11976CRITICAL10The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both ...
CVE-2026-11803HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal...
CVE-2026-11361MEDIUM5.9The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme...
CVE-2026-10599HIGH7.5The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact...
CVE-2026-10524HIGH7.5The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now