Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    Cozy Blocks

    CVE-2026-15393

    Affects you if you run Cozy Blocks up to and including 2.2.11 and your installation has users with the Contributor role or higher.

    An insufficiently sanitized block attribute allows an authenticated user with Contributor rights to inject malicious scripts into pages. The scripts execute whenever someone accesses the affected page. This requires an account that can edit content but does not have full control over the installation.

    To my knowledge, this vulnerability is not actively exploited. The likelihood of exploitation is low. I still classify it as knowledge because a Contributor account is easy to obtain on many installations and the impact can be serious.

    Update Cozy Blocks to 2.2.12. The update closes the hole.

    Affected
    Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
    Fixed in
    2.2.12
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.25 %
    percentile 16.5
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Database for CF7

    CVE-2026-13425

    Affects you if you run Database for CF7 in version 1.2.6 or earlier and a contact form is reachable from the outside. With a contact form, that is the default.

    A stored cross-site scripting hole in the Database for CF7 plugin. An attacker can pass an array to an ordinary text field, such as your name, through the public REST API of Contact Form 7. The plugin stores the input unchecked, and the browser executes the injected script when the page is opened. No login is required, and the hole is reachable from the outside.

    The CVSS score of 7.2 and the low exploitation probability of 0.2 percent sound harmless. They are not. The hole requires no login, and a script running in the context of a WordPress page can take over sessions or create users. The low EPSS number only says that it is not yet exploited at scale, not that it is safe.

    Update the plugin to a version after 1.2.6 as soon as the vendor provides one. No interim fix is known for this hole, only the update helps.

    Affected
    Database for CF7
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.25 %
    percentile 16.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    GTM4WP – A Google Tag Manager (GTM) plugin for WordPress

    CVE-2026-16597

    Affects you if you run GTM4WP version 1.22.3 or older with the WooCommerce order data integration enabled.

    An attacker can place a guest checkout order without an account and store a script in a billing field, such as the first name. That script later executes in the browser of another user when they access the affected page. The vulnerability exists because input from WooCommerce fields is not sufficiently sanitized before being output.

    Update GTM4WP to version 1.22.4.

    Affected
    GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
    Fixed in
    1.22.4
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 15.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Booking System Trafft

    CVE-2026-8791

    Affects you if you have the Booking System Trafft plugin up to version 1.0.17 on your WordPress installation and operate it in agency mode.

    An attacker with a subscriber-level account can exploit a stored cross-site scripting vulnerability to plant scripts on the website. This is done by abusing a missing capability check in the `set_options` AJAX action. The required nonce is visible to any authenticated user on every admin page. The stored script runs on all front-end pages that the plugin includes.

    Update the plugin to a version that closes the vulnerability. The source does not name the fixed release.

    Affected
    Booking System Trafft
    Fixed in
    1.0.18
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.24 %
    percentile 15.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Element Pack Addons for Elementor

    CVE-2026-65502

    Affects you if you run Element Pack Addons for Elementor up to and including version 8.7.13.

    A missing authorization check in the plugin. An attacker can access functions without logging in that are normally reserved for a user with higher privileges. What exactly they can do with it depends on which of the affected functions are active on your installation. The vulnerability is not on the KEV list and the likelihood of exploitation is near zero, which is why it is listed as informational.

    Update to the next version after 8.7.13. The source does not name the exact version with the fix.

    Affected
    Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
    Fixed in
    8.7.14
    CVSS
    5.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 15.1
    Type
    CWE-290
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Event Booking Manager for WooCommerce

    CVE-2026-17166

    Affects you if you run Event Booking Manager for WooCommerce up to and including version 5.3.7 and users with the role Contributor or higher have access to the WordPress backend.

    The plugin does not check whether a user has the necessary permissions during an Ajax call. An authenticated user with the role Contributor or higher can modify the site-wide payment settings. This includes enabling WooCommerce payments, cart redirect behavior, login requirements for checkout, and the status of processed bookings. An attacker could redirect the booking flow or disable payments.

    The vulnerability requires an account. That makes it less urgent than one exploitable from the outside without authentication. It should still be closed before an attacker combines it with another vulnerability that gives them an account.

    Update to version 5.3.8.

    Affected
    Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
    Fixed in
    5.3.8
    CVSS
    4.3
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.23 %
    percentile 14.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    WowStore

    CVE-2026-17162

    Affects you if you run the WowStore plugin in version 4.4.24 or earlier and have registered users with at least a Contributor role.

    An attacker with a Contributor account can store malicious script in a block attribute. The script runs whenever someone visits the affected page. On its own this is annoying but not earth-shattering, because the attacker needs an account. Combined with another vulnerability that provides one, it becomes an effective attack on every visitor to the site.

    Update to version 4.5.0. The source does not name a workaround.

    Affected
    WowStore – Store Builder & Product Blocks for WooCommerce
    Fixed in
    4.5.0
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    WowStore – Store Builder & Product Blocks for WooCommerce

    CVE-2026-17161

    Affects you if you run the WowStore plugin in a version up to 4.4.24 and users with the Contributor role or higher have access to the editor.

    Stored XSS via a block attribute. An authenticated user with at least Contributor privileges can place scripts in the editor that execute in the browser of other visitors when the page is loaded. The save-time sanitization fails because the payload sits inside a JSON comment within a Gutenberg delimiter block and survives that way.

    The attacker needs an account but does not need to be an administrator. That makes the vulnerability relevant in multi-user environments, such as shops with external product maintainers.

    Update to version 4.5.0. The source does not name a workaround.

    Affected
    WowStore – Store Builder & Product Blocks for WooCommerce
    Fixed in
    4.5.0
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Contact Form to Any API

    CVE-2026-15735

    Affects you if you run the Contact Form to Any API plugin in versions up to and including 3.0.6 and your installation has users with the Contributor role or higher that you do not fully control.

    An attacker with a Contributor account can store malicious scripts in the plugin's post meta data. These scripts execute whenever someone accesses the affected page. The attacker needs an account for this, but no administrator privileges. The vulnerability is not listed in the KEV catalog of actively exploited flaws, and the likelihood of widespread exploitation is low at an EPSS of 0.2 %.

    On its own, this is a finding that requires an existing account. In an environment where you do not give the Contributor role to strangers, the risk is manageable. If you do, you should act.

    Update to version 3.0.7.

    Affected
    Contact Form to Any API
    Fixed in
    3.0.7
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    AffiliateWP

    CVE-2026-65515

    Affects you if you run AffiliateWP up to and including version 2.35.0.

    Stored cross-site scripting exploitable without authentication. An attacker can place malicious code in your installation that executes in your visitors' browsers. The plugin is widely deployed and the vulnerability reachable from the outside.

    Update to version 2.35.1.

    Affected
    AffiliateWP
    Fixed in
    2.35.1
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.