2026 CVE Vulnerabilities

51,071 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14862LOW3.7The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo...
CVE-2026-14849LOW3.7The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it...
CVE-2026-14847MEDIUM4.3The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i...
CVE-2026-14845MEDIUM6.1The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re...
CVE-2026-14843MEDIUM5.3The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target...
CVE-2026-14834MEDIUM6.5The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX ...
CVE-2026-14833MEDIUM6.8The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend...
CVE-2026-14830HIGH7.5The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually...
CVE-2026-14554MEDIUM6.5The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them...
CVE-2026-14483CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver...
CVE-2026-14333HIGH7.5The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p...
CVE-2026-14319HIGH7.5The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri...
CVE-2026-14317MEDIUM5.3The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t...
CVE-2026-13609HIGH8.8The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af...
CVE-2026-13393LOW3.5The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item...
CVE-2026-13392HIGH7.2The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a...
CVE-2026-12721HIGH8.6The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us...
CVE-2026-12720HIGH7.5The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ...
CVE-2026-12697MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us...
CVE-2026-12695HIGH8.1The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted...
CVE-2026-12376MEDIUM4.3The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing...
CVE-2026-12251HIGH8.1The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m...
CVE-2026-63223CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i...
CVE-2026-63222HIGH7.5CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us...
CVE-2026-63221CRITICAL9.4CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now