Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
WP CTA
CVE-2026-6089Affects you if you run WP CTA in a version up to and including 2.1.2 and the plugin is available to administrators.
An administrator can make arbitrary web requests from the server through manipulated import data. The address validation allows internal IP ranges, so services on the internal network are reachable. The responses are stored as media attachments in the WordPress library. On its own this is not full access, but a useful stepping stone for attacks on internal systems.
Update to version 2.1.3.
- Affected
- WP CTA – Call Now Button, Sticky Button & Call to Action Builder
- Fixed in
- 2.1.3
- CVSS
- 4.9
source security@wordfence.com - Login required
- yes, administrator
- Likely to be exploited
- 0.28 %
percentile 20.0 - Type
- CWE-918
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
MasterStudy LMS WordPress Plugin
CVE-2026-5060Affects you if you run the MasterStudy LMS WordPress plugin in versions up to and including 3.7.14 and have given out an account with Instructor-level access or higher.
An Instructor can delete arbitrary file attachments through a function meant for removing course covers, because the plugin does not check whether the attachment belongs to the Instructor. An attacker with these privileges can delete other users' attachments by simply trying out sequential IDs, without their consent or knowledge.
Update to version 3.7.24. The source does not name a workaround that prevents deletion without the update.
- Affected
- MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Fixed in
- 3.7.24
- CVSS
- 6.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.22 %
percentile 12.7 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Business Directory Plugin
CVE-2026-61959Affects you if you run the Business Directory Plugin in a version up to 6.4.24 and allow visitors to register as subscribers.
An attacker with a subscriber account can store malicious scripts in directory listings. Anyone who views those listings later runs the script in their own browser. That is enough to hijack sessions or trick administrators into actions they did not intend. The CVSS of 6.5 indicates medium severity, but the low EPSS of 0.2 percent is misleading: once someone has an account, the barrier is low. And a subscriber account is quickly created on many installations.
Update to version 6.4.25. The source does not name a workaround, so only the update helps.
- Affected
- Business Directory Plugin – Easy Listing Directories for WordPress
- Fixed in
- 6.4.25
- CVSS
- 6.5
source audit@patchstack.com - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 11.6 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Survey Form Block
CVE-2026-5626Affects you if you use the Survey Form Block plugin in a version up to and including 1.0.1 on your WordPress installation and run surveys with visitors.
A missing capability check in the get_all_data() function. An attacker with a simple subscriber account can use it to export all survey data and the associated metadata. This is not full access to the site, but a data leak that exposes every participant's answers. The attacker needs an account, but a subscriber account is quickly created if registration is open.
Update the plugin to a version that closes the hole. The source does not name a specific version with the fix, so check the WordPress plugin directory to see if an update is available.
- Affected
- Survey Form Block – collect answers and insights from your audience
- Fixed in
- 1.0.2
- CVSS
- 4.3
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.20 %
percentile 10.0 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
FuseWP
CVE-2026-5582Affects you if you use FuseWP up to and including version 1.1.24.2 and an administrator clicks a crafted link while logged in.
An attacker can toggle sync rules, meaning enable or disable them, without the administrator noticing. To do this, they must trick an administrator into visiting a forged link, for example via email or another website. The vulnerability alone does not grant access to data, but it can disrupt automations that rely on these sync rules.
Update to version 1.1.25.2.
- Affected
- FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)
- Fixed in
- 1.1.25.2
- CVSS
- 4.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.13 %
percentile 3.1 - Type
- CWE-352
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Advanced Responsive Video Embedder
CVE-2026-18072Affects you if you run the Advanced Responsive Video Embedder plugin in version 10.8.7.
A hardcoded backdoor. The plugin compares a submitted value against a checksum stored in its source code. If the checksum matches, the attacker is logged in as any user, administrator included, without username or password. The check runs before any other verification, so no security measure catches it.
Remove the plugin until the vendor releases a clean version. No workaround is known.
- Affected
- Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.59 %
percentile 44.9 - Type
- CWE-506
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
AI Copilot – Content Generator
CVE-2026-65507Affects you if you use the plugin AI Copilot – Content Generator in a version up to and including 1.5.6 on your WordPress site.
A stranger can pose as an administrator without logging in. The flaw is in the plugin's privilege check. An attacker needs no credentials and no account to do this. They get everything an administrator gets.
Update to 1.5.8. The source does not name another fix.
- Affected
- AI Copilot – Content Generator
- Fixed in
- 1.5.8
- CVSS
- 9.8
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.33 %
percentile 25.7 - Type
- CWE-266
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Simply Schedule Appointments
CVE-2026-65508Affects you if you run Simply Schedule Appointments in a version up to and including 1.6.12.10 and the plugin is reachable from the outside.
An unauthenticated SQL injection. A stranger can inject their own database commands without having an account. The plugin handles appointment bookings, and the data behind it is often personal. The CVSS of 9.3 is not an accident.
Update to 1.6.12.11. The source provides no workaround; only the update helps.
- Affected
- Simply Schedule Appointments
- Fixed in
- 1.6.12.11
- CVSS
- 9.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.29 %
percentile 21.4 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
WP OAuth Server (Login with WordPress)
CVE-2026-65520Affects you if you run the WP OAuth Server plugin in version 6.2.0 or older. No login is required for the attack.
An SQL injection that can be exploited from the outside without authentication. An attacker can reach your database. The CVSS of 9.3 reflects that, even though the EPSS likelihood of exploitation is currently low.
The plugin sits on my own systems, so the vulnerability is listed here. For an unauthenticated SQL injection, the rating is always immediate, regardless of EPSS.
Update to version 6.2.1. The source does not name another solution.
- Affected
- WP OAuth Server ( Login with WordPress )
- Fixed in
- 6.2.1
- CVSS
- 9.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.29 %
percentile 21.4 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Formidable Forms Signature Online Contract Automation
CVE-2026-65523Affects you if you run the Formidable Forms Signature Online Contract Automation plugin in a version up to 2.0.1 on your WordPress site.
An insecure direct object reference that requires no login. An attacker can access data not meant for them, such as signed documents belonging to other users. The vulnerability is technically simple to exploit, but the likelihood of exploitation is assessed as low.
Update the plugin to a version that closes the vulnerability. The source does not name the fixed version, so check the update notification in your WordPress installation.
- Affected
- Formidable Forms Signature Online Contract Automation
- Fixed in
- 2.0.2
- CVSS
- 7.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.29 %
percentile 21.0 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.