2026 CVE Vulnerabilities

51,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15250MEDIUM5.3The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated ...
CVE-2026-15240HIGH7.5The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper...
CVE-2026-15235MEDIUM4.3The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking...
CVE-2026-15153MEDIUM6.8The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative ...
CVE-2026-15054LOW3.7The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss...
CVE-2026-14923MEDIUM6.5The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a ...
CVE-2026-14602CRITICAL9The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al...
CVE-2026-14592MEDIUM6.1The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks befor...
CVE-2026-14318MEDIUM6.8The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H...
CVE-2026-14310MEDIUM5.4The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread ...
CVE-2026-14305MEDIUM5.3The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all...
CVE-2026-14239HIGH7.1The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro...
CVE-2026-14231MEDIUM4.3The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX hand...
CVE-2026-14226MEDIUM4.3The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment...
CVE-2026-14223MEDIUM4.3The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust...
CVE-2026-14222LOW3.8The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne...
CVE-2026-14221LOW3.8The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana...
CVE-2026-14207MEDIUM6.1The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field befor...
CVE-2026-14188LOW2.7The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of...
CVE-2026-13395HIGH8.6The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a ...
CVE-2026-13345MEDIUM5.3The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility...
CVE-2026-13344MEDIUM4.8The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta...
CVE-2026-13330MEDIUM6.1The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it ad...
CVE-2026-13178HIGH7.5The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied ...
CVE-2026-13145MEDIUM4.3The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now