Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    Spider Analyser – WordPress搜索引擎蜘蛛分析插件

    CVE-2026-65553

    Affects you if you run the Spider Analyser plugin in any version up to 2.1.3.

    An attacker can run their own code on your server without logging in. The vulnerability is reachable from the outside and rated CVSS 10, the highest severity.

    The source does not name a fixed version or a workaround. Deactivate the plugin until an update appears.

    Affected
    Spider Analyser – WordPress搜索引擎蜘蛛分析插件
    CVSS
    10.0
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.48 %
    percentile 38.9
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Subscriptions for WooCommerce

    CVE-2026-15397

    Affects you if you run Subscriptions for WooCommerce up to and including 2.0.0 and have users with the Shop Manager role or higher.

    A shop manager can install and activate arbitrary plugins from the WordPress.org directory through an unprotected AJAX endpoint. The attacker needs an account, but not administrator privileges. They decide which plugins to pull in. That opens the door to anything an installed plugin can do on the system.

    To my knowledge this vulnerability is not actively exploited. I still classify it as noteworthy because the Shop Manager role exists in many WooCommerce installations and the impact is severe.

    Update to 2.0.1. Then check the list of installed plugins for entries you did not add yourself.

    Affected
    Subscriptions for WooCommerce
    Fixed in
    2.0.1
    CVSS
    7.2
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.31 %
    percentile 23.8
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Improved Save Button

    CVE-2026-16092

    Affects you if you run the Improved Save Button plugin in a version up to and including 1.2.1 and have users with the Author role or higher.

    A SQL injection that does not strike immediately, but on a second step. An authenticated user with at least Author privileges can write malicious code into the database via a custom field. The next time the Save and Duplicate function is called, that code becomes part of a database query and reads out information that does not belong there.

    The vulnerability requires an account. That limits the circle of attackers, but in a multi-user system with many authors it is still dangerous. A single compromised Author is enough to read out the database.

    Update to a version that closes the hole. The source does not name a specific version number, only that all versions up to 1.2.1 are affected. If no update is available yet, take the plugin offline until a fix arrives.

    Affected
    Improved Save Button
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.25 %
    percentile 16.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    HBook – hotel booking system

    CVE-2026-8143

    Affects you if you run the WordPress plugin HBook in any version up to and including 2.1.9.

    An attacker can store malicious code in the country, US state, and Canadian province parameters without logging in. The code is saved and executes whenever someone opens the plugin's customers page in the admin area.

    This is not critical because it requires interaction in the backend. It is listed here because it is exploitable without an account and the plugin runs on my systems.

    The source does not name a fixed version or a workaround. Disable the plugin until an update appears.

    Affected
    HBook - Hotel booking system - WordPress Plugin
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 8.9
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-29

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    Cost Calculator Builder PRO

    CVE-2026-14900

    Affects you if you run Cost Calculator Builder PRO up to and including version 4.0.3 and the site is publicly reachable.

    An unsanitized value from an order parameter is injected directly into a PHP calculation and executed with eval(). An attacker can run their own code on the server without logging in. The only barrier is a security token that the plugin itself emits on every public page.

    Update to version 4.0.4.

    Affected
    Cost Calculator Builder PRO
    Fixed in
    4.0.4
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.69 %
    percentile 49.5
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Extra Checkout Options

    CVE-2026-14270

    Affects you if you run Extra Checkout Options up to and including 2.3.2 and have users with Subscriber access or higher.

    A missing authorization check lets authenticated users with minimal privileges change the list of allowed file types and then upload a PHP file. The upload runs through an endpoint exposed on cart and checkout pages. An attacker with a Subscriber account can execute their own code on the server.

    Update to 2.3.3. Check the uploads directory for PHP files that do not belong there.

    Affected
    Extra Checkout Options - addon for Extra Product Options plugin
    Fixed in
    2.3.3
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.55 %
    percentile 43.0
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Spreadsheet Price Changer for WooCommerce

    CVE-2025-10656

    Affects you if you run the plugin Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light up to version 2.4.37.

    The plugin allows changing prices in the WooCommerce shop via a spreadsheet. A missing authorization check in a function lets attackers create an admin account without logging in.

    Exploitation requires no credentials and no access to the system. An attacker can grant themselves full privileges and take over the shop.

    Update to the latest version of the plugin. Check the WordPress user list for accounts you did not create.

    Affected
    Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.49 %
    percentile 39.8
    Type
    CWE-863
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Wholesale for WooCommerce

    CVE-2026-12144

    Affects you if you run the Wholesale for WooCommerce plugin in version 2.0.5 or older and authors or higher roles have backend access.

    A missing capability check lets any logged-in author assign the administrator role to themselves. The parameter that sets the role is sanitized but not checked against a list of permitted values. So anyone who has an author account or has taken one over becomes an administrator with a single request.

    This is a privilege escalation that requires an existing account. Without author access, nothing happens here. But if another path into your installation exists, such as a stolen author password, this hole is the next step to full takeover.

    Update to the latest version of the plugin and check whether users with author privileges exist that you did not create yourself.

    Affected
    Wholesale for WooCommerce
    Fixed in
    2.0.6
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.37 %
    percentile 29.6
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Meta Box AIO

    CVE-2026-14488

    Affects you if you run Meta Box AIO version 3.8.0 or older with the MB Frontend Submission extension enabled.

    A missing authorization check in the Frontend Submission extension. The handle_request() function executes the delete action without checking whether the caller is logged in or owns the post. The intended nonce check is bypassed because it only fires on Ajax requests, not on template_redirect. An attacker can delete arbitrary posts and pages by appending a post ID to any page that hosts a frontend form.

    This is data loss without authentication. The damage is permanent without a backup.

    Update to version 3.9.0. The source provides no workaround that prevents deletion without the update.

    Affected
    Meta Box AIO
    Fixed in
    3.9.0
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.31 %
    percentile 23.1
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Klubraum Membership Request

    CVE-2026-4604

    Affects you if you run the Klubraum Membership Request plugin for WordPress in any version up to and including 1.1.0.

    A missing capability check in the function that saves settings. Without logging in, an attacker can overwrite the plugin's configuration, including the API token for the Klubraum service. This effectively hijacks the integration between your site and the service.

    Update the plugin to a version that fixes the issue. The source does not name a specific version number, so check for available updates in your WordPress installation.

    Affected
    Klubraum Membership Request
    Fixed in
    1.1.1
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 14.5
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.