2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18049 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ... |
| CVE-2026-18048 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f... |
| CVE-2026-18046 | — | — | — | Aug 12, 2026 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability... |
| CVE-2026-18035 | — | — | — | Aug 12, 2026 | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo... |
| CVE-2026-17013 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it... |
| CVE-2026-16977 | — | — | — | Aug 12, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ... |
| CVE-2026-16737 | — | — | — | Aug 12, 2026 | The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca... |
| CVE-2026-16538 | — | — | — | Aug 12, 2026 | The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top... |
| CVE-2026-16294 | — | — | — | Aug 12, 2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode... |
| CVE-2026-16253 | — | — | — | Aug 12, 2026 | The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto... |
| CVE-2026-16066 | — | — | — | Aug 12, 2026 | The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it ... |
| CVE-2026-16051 | — | — | — | Aug 12, 2026 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re... |
| CVE-2026-15388 | — | — | — | Aug 12, 2026 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability... |
| CVE-2026-15249 | — | — | — | Aug 12, 2026 | The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i... |
| CVE-2026-15039 | — | — | — | Aug 12, 2026 | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all... |
| CVE-2026-14925 | — | — | — | Aug 12, 2026 | The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo... |
| CVE-2026-14859 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a... |
| CVE-2026-14858 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi... |
| CVE-2026-14857 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his... |
| CVE-2026-13613 | — | — | — | Aug 12, 2026 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ... |
| CVE-2026-13612 | — | — | — | Aug 12, 2026 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al... |
| CVE-2026-13177 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user... |
| CVE-2026-13171 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han... |
| CVE-2026-13168 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users... |
| CVE-2026-12976 | — | — | — | Aug 12, 2026 | The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now