Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    Cozy Blocks

    CVE-2026-15950

    Affects you if you run Cozy Blocks in a version up to and including 2.2.11 and have users with the Contributor role or higher.

    An authenticated user with Contributor rights can store malicious scripts in a block attribute. The input is insufficiently sanitized and the output is not escaped, so the script executes in the browser of other visitors. The attacker needs an account, but only the low-level Contributor role. No active exploit is currently known, and the likelihood of exploitation is low.

    Update Cozy Blocks to version 2.2.12.

    Affected
    Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
    Fixed in
    2.2.12
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Kadence Blocks

    CVE-2026-18435

    Affects you if you run Kadence Blocks up to and including 3.7.8 and your WordPress site has users with the Contributor role or higher.

    A Contributor can place a malicious script in the 'toggleIcon' attribute when editing a block. The script executes as soon as someone visits the page. The attacker needs an account, but does not need to be an administrator. Because Kadence Blocks is widely deployed, the vulnerability remains relevant for many installations, even though the bar is higher than for an unprotected endpoint.

    Update Kadence Blocks to 3.7.8.1. Also check whether unexpected Contributor accounts have been created among your users.

    Affected
    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
    Fixed in
    3.7.8.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Meta for WooCommerce

    CVE-2026-66707

    Affects you if you run Meta for WooCommerce in a version up to and including 3.7.5.

    An attacker can exploit a stored cross-site scripting vulnerability without logging in. The malicious script stays on the server and runs in the browser of every visitor who loads the affected page. This allows session takeover, hijacking of administrator accounts, or using the site for phishing.

    Update to version 3.7.6.

    Affected
    Meta for WooCommerce
    Fixed in
    3.7.6
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Debian Security

    PHP

    CVE-2026-17543 and 2 more

    Affects you if you run PHP 8.2, 8.3, 8.4, or 8.5 and pass parameters to database queries that come from outside. That is the case with every WordPress installation.

    PHP 8.3-FPM runs underneath every WordPress installation. The flaw is improper escaping of backslashes in parameters supplied by an attacker. That turns into a SQL injection that directly affects every WordPress installation running on these PHP versions.

    The vulnerability is trivial to exploit. A stranger can reach database contents not meant for them, without needing an account.

    Update PHP to the respective fixed version. If your hoster offers the update, take it. If you self-host, install the update and restart the FPM service.

    Affected
    php8.4
    CVSS
    8.1
    source security@php.net
    Login required
    no
    Likely to be exploited
    0.47 %
    percentile 38.2
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Debian DSA

  5. Act now Wordfence

    GiveWP

    CVE-2026-14318

    Affects you if you run GiveWP in a version below 4.16.3 and users with the GiveWP Worker role or higher can access the donation form settings.

    A stored cross-site scripting vulnerability. A user with the Worker role can place scripts in a template setting. When a donor visits the public form, their browser executes that script. The vulnerability requires an account, but the Worker role is meant for volunteers or temporary helpers, not administrators. That lowers the bar.

    This vulnerability is not on the KEV catalog of actively exploited flaws. The CVSS of 6.8 reflects that a login is required. The EPSS of 0.3% says exploitation in the next 30 days is unlikely.

    Update GiveWP to 4.16.3.

    Affected
    GiveWP – Donation Plugin and Fundraising Platform
    Fixed in
    4.16.3
    CVSS
    6.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, administrator
    Likely to be exploited
    0.32 %
    percentile 24.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Sync Post With Other Site

    CVE-2026-14923

    Affects you if you run the Sync Post With Other Site plugin below version 1.9.3 and have registered users with at least the Contributor role.

    A REST endpoint that creates and updates posts checks authorization incorrectly. An operator precedence flaw means a user with the capability to edit their own posts, such as a Contributor, can instead create, publish, and overwrite arbitrary pages. Content authored by administrators is not protected either.

    The vulnerability is not listed in the CISA KEV catalog of actively exploited vulnerabilities. That does not change the fact that it needs to be closed immediately on any multi-user system.

    Update to version 1.9.3.

    Affected
    Sync Post With Other Site
    Fixed in
    1.9.3
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.26 %
    percentile 17.5
    Type
    CWE-863
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Easy Appointments

    CVE-2026-14222

    Affects you if you run Easy Appointments in a version before 3.12.28 and grant users with the Contributor role access to the backend.

    The plugin lacks a capability check for an action that deletes the booking configuration. A user with Contributor rights can disable the entire booking system. The role is meant for writing posts, not for managing plugins.

    Update Easy Appointments to version 3.12.28.

    Affected
    Easy Appointments
    CVSS
    3.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, administrator
    Likely to be exploited
    0.24 %
    percentile 15.4
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    WP Delicious

    CVE-2026-14305

    Affects you if you run the WP Delicious WordPress plugin in a version earlier than 1.10.2.

    An AJAX endpoint in the plugin does not check whether the caller is authorized. This lets someone without an account modify the metadata of arbitrary posts, specifically a counter and an associated list. This is not data loss, but the values can be inflated arbitrarily and the stored metadata grows without bound.

    Update to version 1.10.2.

    Affected
    WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)
    Fixed in
    1.10.2
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 14.0
    Type
    CWE-287
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Easy Appointments

    CVE-2026-14226

    Affects you if you run Easy Appointments up to and including version 3.12.26 and have registered users, even at the lowest subscriber level.

    A REST endpoint in the plugin does not check whether the requesting user is authorized to view the bookings. Simply having an account is enough. A subscriber can read all bookings, including customer names, schedules, and statuses.

    Update to version 3.12.28.

    Affected
    Easy Appointments
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 13.1
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    LifterLMS

    CVE-2026-14231

    Affects you if you run LifterLMS in a version below 10.0.10 and have registered users with the subscriber role or higher.

    An AJAX handler checks only whether someone is logged in, not whether they have the required capability. A subscriber can use it to read the titles of internal post types, such as coupon codes. This is not full shop access, but it is a data leak that should not happen.

    Update to 10.0.10.

    Affected
    LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
    Fixed in
    10.0.10
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 13.1
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.