Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. This week Wordfence

    WP CTA

    CVE-2026-6089

    Affects you if you run WP CTA in a version up to and including 2.1.2 and the plugin is available to administrators.

    An administrator can make arbitrary web requests from the server through manipulated import data. The address validation allows internal IP ranges, so services on the internal network are reachable. The responses are stored as media attachments in the WordPress library. On its own this is not full access, but a useful stepping stone for attacks on internal systems.

    Update to version 2.1.3.

    Affected
    WP CTA – Call Now Button, Sticky Button & Call to Action Builder
    Fixed in
    2.1.3
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.28 %
    percentile 20.0
    Type
    CWE-918
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    MasterStudy LMS WordPress Plugin

    CVE-2026-5060

    Affects you if you run the MasterStudy LMS WordPress plugin in versions up to and including 3.7.14 and have given out an account with Instructor-level access or higher.

    An Instructor can delete arbitrary file attachments through a function meant for removing course covers, because the plugin does not check whether the attachment belongs to the Instructor. An attacker with these privileges can delete other users' attachments by simply trying out sequential IDs, without their consent or knowledge.

    Update to version 3.7.24. The source does not name a workaround that prevents deletion without the update.

    Affected
    MasterStudy LMS WordPress Plugin – for Online Courses and Education
    Fixed in
    3.7.24
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 12.7
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. This week Wordfence

    Business Directory Plugin

    CVE-2026-61959

    Affects you if you run the Business Directory Plugin in a version up to 6.4.24 and allow visitors to register as subscribers.

    An attacker with a subscriber account can store malicious scripts in directory listings. Anyone who views those listings later runs the script in their own browser. That is enough to hijack sessions or trick administrators into actions they did not intend. The CVSS of 6.5 indicates medium severity, but the low EPSS of 0.2 percent is misleading: once someone has an account, the barrier is low. And a subscriber account is quickly created on many installations.

    Update to version 6.4.25. The source does not name a workaround, so only the update helps.

    Affected
    Business Directory Plugin – Easy Listing Directories for WordPress
    Fixed in
    6.4.25
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 11.6
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. This week Wordfence

    Survey Form Block

    CVE-2026-5626

    Affects you if you use the Survey Form Block plugin in a version up to and including 1.0.1 on your WordPress installation and run surveys with visitors.

    A missing capability check in the get_all_data() function. An attacker with a simple subscriber account can use it to export all survey data and the associated metadata. This is not full access to the site, but a data leak that exposes every participant's answers. The attacker needs an account, but a subscriber account is quickly created if registration is open.

    Update the plugin to a version that closes the hole. The source does not name a specific version with the fix, so check the WordPress plugin directory to see if an update is available.

    Affected
    Survey Form Block – collect answers and insights from your audience
    Fixed in
    1.0.2
    CVSS
    4.3
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. This week Wordfence

    FuseWP

    CVE-2026-5582

    Affects you if you use FuseWP up to and including version 1.1.24.2 and an administrator clicks a crafted link while logged in.

    An attacker can toggle sync rules, meaning enable or disable them, without the administrator noticing. To do this, they must trick an administrator into visiting a forged link, for example via email or another website. The vulnerability alone does not grant access to data, but it can disrupt automations that rely on these sync rules.

    Update to version 1.1.25.2.

    Affected
    FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)
    Fixed in
    1.1.25.2
    CVSS
    4.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.13 %
    percentile 3.1
    Type
    CWE-352
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Advanced Responsive Video Embedder

    CVE-2026-18072

    Affects you if you run the Advanced Responsive Video Embedder plugin in version 10.8.7.

    A hardcoded backdoor. The plugin compares a submitted value against a checksum stored in its source code. If the checksum matches, the attacker is logged in as any user, administrator included, without username or password. The check runs before any other verification, so no security measure catches it.

    Remove the plugin until the vendor releases a clean version. No workaround is known.

    Affected
    Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.59 %
    percentile 44.9
    Type
    CWE-506
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    AI Copilot – Content Generator

    CVE-2026-65507

    Affects you if you use the plugin AI Copilot – Content Generator in a version up to and including 1.5.6 on your WordPress site.

    A stranger can pose as an administrator without logging in. The flaw is in the plugin's privilege check. An attacker needs no credentials and no account to do this. They get everything an administrator gets.

    Update to 1.5.8. The source does not name another fix.

    Affected
    AI Copilot – Content Generator
    Fixed in
    1.5.8
    CVSS
    9.8
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 25.7
    Type
    CWE-266
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Simply Schedule Appointments

    CVE-2026-65508

    Affects you if you run Simply Schedule Appointments in a version up to and including 1.6.12.10 and the plugin is reachable from the outside.

    An unauthenticated SQL injection. A stranger can inject their own database commands without having an account. The plugin handles appointment bookings, and the data behind it is often personal. The CVSS of 9.3 is not an accident.

    Update to 1.6.12.11. The source provides no workaround; only the update helps.

    Affected
    Simply Schedule Appointments
    Fixed in
    1.6.12.11
    CVSS
    9.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.4
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    WP OAuth Server (Login with WordPress)

    CVE-2026-65520

    Affects you if you run the WP OAuth Server plugin in version 6.2.0 or older. No login is required for the attack.

    An SQL injection that can be exploited from the outside without authentication. An attacker can reach your database. The CVSS of 9.3 reflects that, even though the EPSS likelihood of exploitation is currently low.

    The plugin sits on my own systems, so the vulnerability is listed here. For an unauthenticated SQL injection, the rating is always immediate, regardless of EPSS.

    Update to version 6.2.1. The source does not name another solution.

    Affected
    WP OAuth Server ( Login with WordPress )
    Fixed in
    6.2.1
    CVSS
    9.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.4
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    Formidable Forms Signature Online Contract Automation

    CVE-2026-65523

    Affects you if you run the Formidable Forms Signature Online Contract Automation plugin in a version up to 2.0.1 on your WordPress site.

    An insecure direct object reference that requires no login. An attacker can access data not meant for them, such as signed documents belonging to other users. The vulnerability is technically simple to exploit, but the likelihood of exploitation is assessed as low.

    Update the plugin to a version that closes the vulnerability. The source does not name the fixed version, so check the update notification in your WordPress installation.

    Affected
    Formidable Forms Signature Online Contract Automation
    Fixed in
    2.0.2
    CVSS
    7.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.0
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.