2026 CVE Vulnerabilities

51,002 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14823LOW2.2The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it...
CVE-2026-14822MEDIUM5.3The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i...
CVE-2026-14596HIGH8.8The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the...
CVE-2026-14561MEDIUM6.5The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden...
CVE-2026-14315MEDIUM6.5The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i...
CVE-2026-14309HIGH8.1The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been ...
CVE-2026-14292MEDIUM5.4The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t...
CVE-2026-14214LOW2.7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr...
CVE-2026-14197LOW3.8The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket...
CVE-2026-14195LOW2.7The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p...
CVE-2026-13729MEDIUM4.3The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat...
CVE-2026-13725HIGH7.1The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user ...
CVE-2026-13604MEDIUM5.3The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit...
CVE-2026-13596CRITICAL9.1The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied paramete...
CVE-2026-13329MEDIUM6.5The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va...
CVE-2026-13158HIGH7.2The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo...
CVE-2026-13157HIGH7.2The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import ...
CVE-2026-12966MEDIUM5.3The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted ...
CVE-2026-12696MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in...
CVE-2026-11882LOW3.7The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes...
CVE-2026-10827LOW3.5The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi...
CVE-2026-3141CRITICAL9.1The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec...
CVE-2026-7623MEDIUM6.4The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cros...
CVE-2026-15414HIGH8.8The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl...
CVE-2026-15403MEDIUM4.9The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now