2026 CVE Vulnerabilities
53,332 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2312 | MEDIUM | 4.3 | 0.2% | Feb 14, 2026 | The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2026-1512 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-1258 | MEDIUM | 4.9 | 0.4% | Feb 14, 2026 | The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates'... |
| CVE-2026-1254 | MEDIUM | 4.3 | 0.2% | Feb 14, 2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all ... |
| CVE-2026-1249 | MEDIUM | 5 | 0.2% | Feb 14, 2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side ... |
| CVE-2026-0550 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' short... |
| CVE-2026-2022 | MEDIUM | 4.3 | 0.3% | Feb 14, 2026 | The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t... |
| CVE-2026-1987 | MEDIUM | 5.4 | 0.3% | Feb 14, 2026 | The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... |
| CVE-2026-1985 | MEDIUM | 6.4 | 0.3% | Feb 14, 2026 | The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all ve... |
| CVE-2026-1944 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2026-1939 | MEDIUM | 6.4 | 0.3% | Feb 14, 2026 | The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` sh... |
| CVE-2026-1915 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'ply... |
| CVE-2026-1910 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-1905 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 's... |
| CVE-2026-1903 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute ... |
| CVE-2026-1901 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcod... |
| CVE-2026-1796 | MEDIUM | 6.1 | 0.2% | Feb 14, 2026 | The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up ... |
| CVE-2026-1795 | MEDIUM | 6.1 | 0.3% | Feb 14, 2026 | The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all version... |
| CVE-2026-1792 | MEDIUM | 6.1 | 0.2% | Feb 14, 2026 | The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to,... |
| CVE-2026-1394 | MEDIUM | 4.3 | 0.2% | Feb 14, 2026 | The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1303 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including... |
| CVE-2026-1187 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the... |
| CVE-2026-1096 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitu... |
| CVE-2026-0751 | MEDIUM | 6.4 | 0.3% | Feb 14, 2026 | The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr... |
| CVE-2026-0745 | MEDIUM | 5.5 | 0.3% | Feb 14, 2026 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now