2026 CVE Vulnerabilities

51,000 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15951MEDIUM4.9The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and...
CVE-2026-15950MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15662MEDIUM6.4The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2026-15649MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho...
CVE-2026-15645MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'na...
CVE-2026-15644MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'st...
CVE-2026-15601MEDIUM4.9The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi...
CVE-2026-15450HIGH8.1The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav...
CVE-2026-15052HIGH7.2The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-15018MEDIUM5.3The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor...
CVE-2026-13458MEDIUM6.4The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML A...
CVE-2026-11995MEDIUM5.3The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress ...
CVE-2026-10782MEDIUM4.3The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-2916MEDIUM4.3The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2026-15988HIGH8.8The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-15932MEDIUM5.3The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download...
CVE-2026-15368HIGH8.1The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after use...
CVE-2026-15262MEDIUM5.4The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out...
CVE-2026-15244HIGH7.2The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con...
CVE-2026-15234MEDIUM5.4The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin...
CVE-2026-14840MEDIUM5.3The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien...
CVE-2026-14839HIGH7.5The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public R...
CVE-2026-14836HIGH8.1The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset...
CVE-2026-14823LOW2.2The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it...
CVE-2026-14822MEDIUM5.3The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now