Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. Act now Wordfence

    Easy Appointments

    CVE-2026-14223

    Affects you if you run Easy Appointments up to and including version 3.12.26 and have users with the subscriber role or higher on your site.

    Insufficiently protected access to customer data. A logged-in user with minimal privileges can read any customer's personal information by simply iterating through identifiers. The vulnerability is not exploitable anonymously from the outside, but anyone with an account, even a subscriber, can use it. That makes it dangerous in membership areas and on sites with open registration.

    Update to version 3.12.28. The source does not name a workaround that prevents the reading without the update.

    Affected
    Easy Appointments
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    Bit Form

    CVE-2026-15054

    Affects you if you run Bit Form prior to version 3.1.2 and have forms that are deactivated or unpublished but still have workflows attached.

    Bit Form does not check whether a form is active when handling public submissions. An attacker can submit entries to a deactivated form and trigger attached workflows such as email notifications, without logging in. This is not a data leak, but it lets someone fire workflows the operator deliberately took offline.

    Update to 3.1.2.

    Affected
    Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder
    Fixed in
    3.1.2
    CVSS
    3.7
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.20 %
    percentile 10.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    LifterLMS

    CVE-2026-14207

    Affects you if you run LifterLMS up to version 10.0.9 and have users with the course editor role or higher.

    A course editor can place JavaScript in a course pricing field. The plugin does not strip it before saving. When an administrator views the course later, the script runs in their session. The editor can then act on behalf of the administrator, change settings, or create additional users.

    The vulnerability requires a trusted role, which keeps the CVSS score low. In learning environments with many course editors, however, trust is spread wide, and the jump from editor to administrator is short.

    Update to version 10.0.10.

    Affected
    LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
    Fixed in
    10.0.10
    CVSS
    6.1
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 9.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Tutor LMS – eLearning and online course solution

    CVE-2026-14310

    Affects you if you run Tutor LMS in a version before 4.0.0 and have courses with the Q&A feature enabled for participants.

    A flaw in the authorization check. An authenticated user with subscriber rights can read the Q&A threads of other courses and inject their own replies. Access to a single course is enough. Content meant only for specific participants is exposed, and discussions can be undermined with false answers.

    Update to version 4.0.0. The source does not provide a workaround.

    Affected
    Tutor LMS – eLearning and online course solution
    Fixed in
    4.0.0
    CVSS
    5.4
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.18 %
    percentile 7.2
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Fluent Forms

    CVE-2026-17567

    Affects you if you run Fluent Forms up to version 6.2.8 and handle payments through the form.

    An insufficiently protected access to payment receipts. An attacker can guess valid transaction hashes without logging in, because the required components such as form ID and submission ID are either observable or guessable. The weakness is in the transaction parameter, which is not sufficiently protected against brute-forcing.

    This allows viewing other customers' payment data: name, email, billing address, ordered items, payment method, and payment status. The vulnerability requires no account and is exploitable with little effort.

    Update Fluent Forms to version 6.2.9. The source does not name another fix.

    Affected
    Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    Fixed in
    6.2.9
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.38 %
    percentile 30.5
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    RegistrationMagic

    CVE-2026-15255

    Affects you if you run RegistrationMagic in a version before 6.0.9.4 and the plugin stores form data that should not fall into the wrong hands.

    The plugin does not verify that a one-time password presented in a cookie belongs to the identity whose form data is being requested. An attacker without an account can read other users' submitted data, including personal information. No active exploitation is currently known, and the likelihood of exploitation is in the low range.

    Update to version 6.0.9.4.

    Affected
    RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
    Fixed in
    6.0.9.4
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.20 %
    percentile 10.3
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    RegistrationMagic

    CVE-2026-15257

    Affects you if you run RegistrationMagic in a version before 6.0.9.4 and the plugin accepts form submissions from visitors.

    The plugin skips the check of whether a sender is authorized when editing form data. A stranger can overwrite other users' submitted data without logging in and change the profile fields of the associated WordPress accounts. Administrator accounts are not affected.

    The vulnerability is not on the KEV list and the likelihood of exploitation is 0.2 percent. I still classify it as awareness because it requires no login and undermines data integrity.

    Update to version 6.0.9.4.

    Affected
    RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
    Fixed in
    6.0.9.4
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 8.8
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-30

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Easy Appointments

    CVE-2026-14224

    Affects you if you run Easy Appointments up to version 3.12.26 and registered users can book their own appointments.

    An access control flaw. The plugin does not verify that the appointment targeted by its customer-data update action belongs to the current user. It relies on a shared nonce that any authenticated user can obtain from their own booking form.

    An attacker with a basic subscriber account can reuse that nonce to overwrite another appointment's name, email, phone number, and description. Because the plugin later treats this metadata as the appointment's contact data, a subsequent status change by an administrator can cause the victim's entered data to be sent to the attacker.

    Update Easy Appointments to version 3.12.28.

    Affected
    Easy Appointments
    CVSS
    5.4
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.15 %
    percentile 4.3
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Admin and Site Enhancements (ASE) Pro

    CVE-2026-16610

    Affects you if you run Admin and Site Enhancements (ASE) Pro up to and including version 8.9.0 and the [post_cf_form] shortcode is placed on at least one publicly accessible page.

    An attacker can execute arbitrary code on the server without logging in. The [post_cf_form] shortcode accepts input and passes it unchecked to a function that executes it directly. The capability check is missing, and a captcha can be bypassed.

    Update to the version that closes the vulnerability. The source does not name the fixed release, so please check with the vendor directly.

    Affected
    Admin and Site Enhancements (ASE) Pro
    Fixed in
    8.9.1
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.58 %
    percentile 44.5
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    BuddyPress

    CVE-2026-1360

    Affects you if you run BuddyPress up to and including 14.5.0 and hand out subscriber-level accounts. In an active BuddyPress network, that is the norm.

    A deserialization of untrusted data in the function that reads profile fields. A logged-in user with subscriber rights can inject an arbitrary PHP object through a textbox field. Whether that turns into code execution depends on a suitable POP chain being present in the WordPress environment. That is not guaranteed, but it cannot be ruled out either.

    The vulnerability is rated 7.5 and the likelihood of exploitation is low. It still belongs on the list because an attacker only needs an account with minimal rights, and the worst case is full takeover.

    Update BuddyPress to the version that fixes the issue. No workaround is known; only the update helps.

    Affected
    BuddyPress
    CVSS
    7.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.57 %
    percentile 44.1
    Type
    CWE-502
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.