2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1242MEDIUM4.3The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callb...
CVE-2026-15947MEDIUM4.3The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2026-15946MEDIUM4.3The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ...
CVE-2026-15463MEDIUM6.1The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2026-15098MEDIUM6.4The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortc...
CVE-2026-13770MEDIUM6.4The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vul...
CVE-2026-13200MEDIUM6.5The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, ...
CVE-2026-13191MEDIUM6.5The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up t...
CVE-2026-12402MEDIUM4.4The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' S...
CVE-2026-11899MEDIUM4.3The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorizat...
CVE-2026-11608MEDIUM6.1The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param...
CVE-2026-92435MEDIUM5.3The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required ...
CVE-2026-92430MEDIUM5.3The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the aut...
CVE-2026-92425MEDIUM5.5The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-leve...
CVE-2026-92421MEDIUM4.7The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the hos...
CVE-2026-92099MEDIUM6.5The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied que...
CVE-2026-91847MEDIUM4.8The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester ow...
CVE-2026-84750MEDIUM6.5The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo...
CVE-2026-19860MEDIUM5.5The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PH...
CVE-2026-16557MEDIUM4.3The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-build...
CVE-2026-92967MEDIUM6.1The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions...
CVE-2026-89334MEDIUM6.5The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to auth...
CVE-2026-89333MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-89093MEDIUM5.3The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info...
CVE-2026-89081MEDIUM6.1The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now