2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1242 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callb... |
| CVE-2026-15947 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2026-15946 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ... |
| CVE-2026-15463 | MEDIUM | 6.1 | 0.1% | Sep 19, 2026 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2026-15098 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortc... |
| CVE-2026-13770 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vul... |
| CVE-2026-13200 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, ... |
| CVE-2026-13191 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up t... |
| CVE-2026-12402 | MEDIUM | 4.4 | 0.2% | Sep 19, 2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' S... |
| CVE-2026-11899 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorizat... |
| CVE-2026-11608 | MEDIUM | 6.1 | 0.3% | Sep 19, 2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param... |
| CVE-2026-92435 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required ... |
| CVE-2026-92430 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the aut... |
| CVE-2026-92425 | MEDIUM | 5.5 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-leve... |
| CVE-2026-92421 | MEDIUM | 4.7 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the hos... |
| CVE-2026-92099 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied que... |
| CVE-2026-91847 | MEDIUM | 4.8 | 0.1% | Sep 19, 2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester ow... |
| CVE-2026-84750 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo... |
| CVE-2026-19860 | MEDIUM | 5.5 | 0.2% | Sep 19, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PH... |
| CVE-2026-16557 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-build... |
| CVE-2026-92967 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions... |
| CVE-2026-89334 | MEDIUM | 6.5 | 0.4% | Sep 19, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to auth... |
| CVE-2026-89333 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-89093 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info... |
| CVE-2026-89081 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now