2026 CVE Vulnerabilities

53,332 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2312MEDIUM4.3The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2026-1512MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-1258MEDIUM4.9The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates'...
CVE-2026-1254MEDIUM4.3The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all ...
CVE-2026-1249MEDIUM5The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side ...
CVE-2026-0550MEDIUM6.4The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' short...
CVE-2026-2022MEDIUM4.3The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t...
CVE-2026-1987MEDIUM5.4The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i...
CVE-2026-1985MEDIUM6.4The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all ve...
CVE-2026-1944MEDIUM5.3The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1939MEDIUM6.4The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` sh...
CVE-2026-1915MEDIUM6.4The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'ply...
CVE-2026-1910MEDIUM6.4The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-1905MEDIUM6.4The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 's...
CVE-2026-1903MEDIUM6.4The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute ...
CVE-2026-1901MEDIUM6.4The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcod...
CVE-2026-1796MEDIUM6.1The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up ...
CVE-2026-1795MEDIUM6.1The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all version...
CVE-2026-1792MEDIUM6.1The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to,...
CVE-2026-1394MEDIUM4.3The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1303MEDIUM5.3The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including...
CVE-2026-1187MEDIUM6.4The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the...
CVE-2026-1096MEDIUM6.4The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitu...
CVE-2026-0751MEDIUM6.4The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr...
CVE-2026-0745MEDIUM5.5The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now