2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-17580MEDIUM6.5The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem...
CVE-2026-17571MEDIUM6.1The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-17555MEDIUM4.9The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers...
CVE-2026-16685MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in...
CVE-2026-16684MEDIUM6.4The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact...
CVE-2026-16614MEDIUM4.9The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL ...
CVE-2026-16091MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-16090MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-16087MEDIUM6.5The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec...
CVE-2026-15951MEDIUM4.9The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and...
CVE-2026-15950MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15662MEDIUM6.4The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2026-15649MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho...
CVE-2026-15645MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'na...
CVE-2026-15644MEDIUM6.4The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'st...
CVE-2026-15601MEDIUM4.9The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi...
CVE-2026-15018MEDIUM5.3The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor...
CVE-2026-13458MEDIUM6.4The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML A...
CVE-2026-11995MEDIUM5.3The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress ...
CVE-2026-10782MEDIUM4.3The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-2916MEDIUM4.3The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2026-15932MEDIUM5.3The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download...
CVE-2026-15262MEDIUM5.4The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out...
CVE-2026-15234MEDIUM5.4The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin...
CVE-2026-14840MEDIUM5.3The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now