Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
Act now Wordfence
Easy Appointments
CVE-2026-14223Affects you if you run Easy Appointments up to and including version 3.12.26 and have users with the subscriber role or higher on your site.
Insufficiently protected access to customer data. A logged-in user with minimal privileges can read any customer's personal information by simply iterating through identifiers. The vulnerability is not exploitable anonymously from the outside, but anyone with an account, even a subscriber, can use it. That makes it dangerous in membership areas and on sites with open registration.
Update to version 3.12.28. The source does not name a workaround that prevents the reading without the update.
- Affected
- Easy Appointments
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 10.8 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Bit Form
CVE-2026-15054Affects you if you run Bit Form prior to version 3.1.2 and have forms that are deactivated or unpublished but still have workflows attached.
Bit Form does not check whether a form is active when handling public submissions. An attacker can submit entries to a deactivated form and trigger attached workflows such as email notifications, without logging in. This is not a data leak, but it lets someone fire workflows the operator deliberately took offline.
Update to 3.1.2.
- Affected
- Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder
- Fixed in
- 3.1.2
- CVSS
- 3.7
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.20 %
percentile 10.2 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
LifterLMS
CVE-2026-14207Affects you if you run LifterLMS up to version 10.0.9 and have users with the course editor role or higher.
A course editor can place JavaScript in a course pricing field. The plugin does not strip it before saving. When an administrator views the course later, the script runs in their session. The editor can then act on behalf of the administrator, change settings, or create additional users.
The vulnerability requires a trusted role, which keeps the CVSS score low. In learning environments with many course editors, however, trust is spread wide, and the jump from editor to administrator is short.
Update to version 10.0.10.
- Affected
- LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
- Fixed in
- 10.0.10
- CVSS
- 6.1
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 9.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Tutor LMS – eLearning and online course solution
CVE-2026-14310Affects you if you run Tutor LMS in a version before 4.0.0 and have courses with the Q&A feature enabled for participants.
A flaw in the authorization check. An authenticated user with subscriber rights can read the Q&A threads of other courses and inject their own replies. Access to a single course is enough. Content meant only for specific participants is exposed, and discussions can be undermined with false answers.
Update to version 4.0.0. The source does not provide a workaround.
- Affected
- Tutor LMS – eLearning and online course solution
- Fixed in
- 4.0.0
- CVSS
- 5.4
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.18 %
percentile 7.2 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Fluent Forms
CVE-2026-17567Affects you if you run Fluent Forms up to version 6.2.8 and handle payments through the form.
An insufficiently protected access to payment receipts. An attacker can guess valid transaction hashes without logging in, because the required components such as form ID and submission ID are either observable or guessable. The weakness is in the transaction parameter, which is not sufficiently protected against brute-forcing.
This allows viewing other customers' payment data: name, email, billing address, ordered items, payment method, and payment status. The vulnerability requires no account and is exploitable with little effort.
Update Fluent Forms to version 6.2.9. The source does not name another fix.
- Affected
- Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Fixed in
- 6.2.9
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.38 %
percentile 30.5 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
RegistrationMagic
CVE-2026-15255Affects you if you run RegistrationMagic in a version before 6.0.9.4 and the plugin stores form data that should not fall into the wrong hands.
The plugin does not verify that a one-time password presented in a cookie belongs to the identity whose form data is being requested. An attacker without an account can read other users' submitted data, including personal information. No active exploitation is currently known, and the likelihood of exploitation is in the low range.
Update to version 6.0.9.4.
- Affected
- RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
- Fixed in
- 6.0.9.4
- CVSS
- 5.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.20 %
percentile 10.3 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
RegistrationMagic
CVE-2026-15257Affects you if you run RegistrationMagic in a version before 6.0.9.4 and the plugin accepts form submissions from visitors.
The plugin skips the check of whether a sender is authorized when editing form data. A stranger can overwrite other users' submitted data without logging in and change the profile fields of the associated WordPress accounts. Administrator accounts are not affected.
The vulnerability is not on the KEV list and the likelihood of exploitation is 0.2 percent. I still classify it as awareness because it requires no login and undermines data integrity.
Update to version 6.0.9.4.
- Affected
- RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
- Fixed in
- 6.0.9.4
- CVSS
- 5.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 8.8 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Easy Appointments
CVE-2026-14224Affects you if you run Easy Appointments up to version 3.12.26 and registered users can book their own appointments.
An access control flaw. The plugin does not verify that the appointment targeted by its customer-data update action belongs to the current user. It relies on a shared nonce that any authenticated user can obtain from their own booking form.
An attacker with a basic subscriber account can reuse that nonce to overwrite another appointment's name, email, phone number, and description. Because the plugin later treats this metadata as the appointment's contact data, a subsequent status change by an administrator can cause the victim's entered data to be sent to the attacker.
Update Easy Appointments to version 3.12.28.
- Affected
- Easy Appointments
- CVSS
- 5.4
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.15 %
percentile 4.3 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-29
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Admin and Site Enhancements (ASE) Pro
CVE-2026-16610Affects you if you run Admin and Site Enhancements (ASE) Pro up to and including version 8.9.0 and the [post_cf_form] shortcode is placed on at least one publicly accessible page.
An attacker can execute arbitrary code on the server without logging in. The [post_cf_form] shortcode accepts input and passes it unchecked to a function that executes it directly. The capability check is missing, and a captcha can be bypassed.
Update to the version that closes the vulnerability. The source does not name the fixed release, so please check with the vendor directly.
- Affected
- Admin and Site Enhancements (ASE) Pro
- Fixed in
- 8.9.1
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.58 %
percentile 44.5 - Type
- CWE-434
- Actively exploited
- not on the KEV list
- Published
- 2026-07-29
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
BuddyPress
CVE-2026-1360Affects you if you run BuddyPress up to and including 14.5.0 and hand out subscriber-level accounts. In an active BuddyPress network, that is the norm.
A deserialization of untrusted data in the function that reads profile fields. A logged-in user with subscriber rights can inject an arbitrary PHP object through a textbox field. Whether that turns into code execution depends on a suitable POP chain being present in the WordPress environment. That is not guaranteed, but it cannot be ruled out either.
The vulnerability is rated 7.5 and the likelihood of exploitation is low. It still belongs on the list because an attacker only needs an account with minimal rights, and the worst case is full takeover.
Update BuddyPress to the version that fixes the issue. No workaround is known; only the update helps.
- Affected
- BuddyPress
- CVSS
- 7.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.57 %
percentile 44.1 - Type
- CWE-502
- Actively exploited
- not on the KEV list
- Published
- 2026-07-29
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.