2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39485 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con... |
| CVE-2026-39484 | MEDIUM | 4.7 | 0.2% | Apr 8, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phis... |
| CVE-2026-39483 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa ... |
| CVE-2026-39482 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post ... |
| CVE-2026-39477 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-39476 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu... |
| CVE-2026-39473 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows R... |
| CVE-2026-39469 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela... |
| CVE-2026-39464 | MEDIUM | 5.5 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by ... |
| CVE-2026-1396 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magi... |
| CVE-2026-4655 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Imag... |
| CVE-2026-4654 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object R... |
| CVE-2026-4330 | MEDIUM | 4.3 | 0.5% | Apr 8, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u... |
| CVE-2026-5508 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in ... |
| CVE-2026-5506 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all vers... |
| CVE-2026-5169 | MEDIUM | 4.4 | 0.3% | Apr 8, 2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade... |
| CVE-2026-5167 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authoriza... |
| CVE-2026-4871 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after... |
| CVE-2026-4141 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-3781 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all version... |
| CVE-2026-3618 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attr... |
| CVE-2026-3594 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2026-3480 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. ... |
| CVE-2026-3477 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including ... |
| CVE-2026-3142 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now