LiveActive security incident?Get immediate response
CVE archive

February 2026

Browse CVE records published in February 2026, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3072 matching CVEs · Page 13 of 62.

Medium · CVSS 4.3

CVE-2026-25402: WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 16.011.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0.

Published Feb 19, 2026 · Updated Apr 28, 2026

Medium · CVSS 4.7

CVE-2026-25392: WordPress Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress plugin <= 1.4.0 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KaizenCoders Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress update-urls allows Phishing.This issue affects Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress: from n/a through <= 1.4.3.

Published Feb 19, 2026 · Updated Apr 28, 2026