2026 CVE Vulnerabilities

51,132 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14226MEDIUM4.3The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment...
CVE-2026-14223MEDIUM4.3The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust...
CVE-2026-14222LOW3.8The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne...
CVE-2026-14221LOW3.8The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana...
CVE-2026-14207MEDIUM6.1The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field befor...
CVE-2026-14188LOW2.7The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of...
CVE-2026-13395HIGH8.6The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a ...
CVE-2026-13345MEDIUM5.3The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility...
CVE-2026-13344MEDIUM4.8The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta...
CVE-2026-13330MEDIUM6.1The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it ad...
CVE-2026-13178HIGH7.5The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied ...
CVE-2026-13145MEDIUM4.3The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa...
CVE-2026-13143MEDIUM5.3The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal po...
CVE-2026-12687HIGH7.5The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th...
CVE-2026-12500HIGH7.5The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a...
CVE-2026-11881MEDIUM6.1The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration setting...
CVE-2026-11870MEDIUM5.4The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a ...
CVE-2026-11867MEDIUM6.5The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term ...
CVE-2026-11782MEDIUM5.9The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w...
CVE-2026-67248HIGH8.8A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because ...
CVE-2026-67247MEDIUM6.5A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle...
CVE-2026-67246MEDIUM6.5A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro...
CVE-2026-67245HIGH8.1A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled...
CVE-2026-1360HIGH7.5The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ...
CVE-2026-16610CRITICAL9.8The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now