Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Cozy Blocks
CVE-2026-15393Affects you if you run Cozy Blocks up to and including 2.2.11 and your installation has users with the Contributor role or higher.
An insufficiently sanitized block attribute allows an authenticated user with Contributor rights to inject malicious scripts into pages. The scripts execute whenever someone accesses the affected page. This requires an account that can edit content but does not have full control over the installation.
To my knowledge, this vulnerability is not actively exploited. The likelihood of exploitation is low. I still classify it as knowledge because a Contributor account is easy to obtain on many installations and the impact can be serious.
Update Cozy Blocks to 2.2.12. The update closes the hole.
- Affected
- Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
- Fixed in
- 2.2.12
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.25 %
percentile 16.5 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Database for CF7
CVE-2026-13425Affects you if you run Database for CF7 in version 1.2.6 or earlier and a contact form is reachable from the outside. With a contact form, that is the default.
A stored cross-site scripting hole in the Database for CF7 plugin. An attacker can pass an array to an ordinary text field, such as your name, through the public REST API of Contact Form 7. The plugin stores the input unchecked, and the browser executes the injected script when the page is opened. No login is required, and the hole is reachable from the outside.
The CVSS score of 7.2 and the low exploitation probability of 0.2 percent sound harmless. They are not. The hole requires no login, and a script running in the context of a WordPress page can take over sessions or create users. The low EPSS number only says that it is not yet exploited at scale, not that it is safe.
Update the plugin to a version after 1.2.6 as soon as the vendor provides one. No interim fix is known for this hole, only the update helps.
- Affected
- Database for CF7
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.25 %
percentile 16.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
CVE-2026-16597Affects you if you run GTM4WP version 1.22.3 or older with the WooCommerce order data integration enabled.
An attacker can place a guest checkout order without an account and store a script in a billing field, such as the first name. That script later executes in the browser of another user when they access the affected page. The vulnerability exists because input from WooCommerce fields is not sufficiently sanitized before being output.
Update GTM4WP to version 1.22.4.
- Affected
- GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
- Fixed in
- 1.22.4
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 15.3 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Booking System Trafft
CVE-2026-8791Affects you if you have the Booking System Trafft plugin up to version 1.0.17 on your WordPress installation and operate it in agency mode.
An attacker with a subscriber-level account can exploit a stored cross-site scripting vulnerability to plant scripts on the website. This is done by abusing a missing capability check in the `set_options` AJAX action. The required nonce is visible to any authenticated user on every admin page. The stored script runs on all front-end pages that the plugin includes.
Update the plugin to a version that closes the vulnerability. The source does not name the fixed release.
- Affected
- Booking System Trafft
- Fixed in
- 1.0.18
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.24 %
percentile 15.3 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Element Pack Addons for Elementor
CVE-2026-65502Affects you if you run Element Pack Addons for Elementor up to and including version 8.7.13.
A missing authorization check in the plugin. An attacker can access functions without logging in that are normally reserved for a user with higher privileges. What exactly they can do with it depends on which of the affected functions are active on your installation. The vulnerability is not on the KEV list and the likelihood of exploitation is near zero, which is why it is listed as informational.
Update to the next version after 8.7.13. The source does not name the exact version with the fix.
- Affected
- Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
- Fixed in
- 8.7.14
- CVSS
- 5.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 15.1 - Type
- CWE-290
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Event Booking Manager for WooCommerce
CVE-2026-17166Affects you if you run Event Booking Manager for WooCommerce up to and including version 5.3.7 and users with the role Contributor or higher have access to the WordPress backend.
The plugin does not check whether a user has the necessary permissions during an Ajax call. An authenticated user with the role Contributor or higher can modify the site-wide payment settings. This includes enabling WooCommerce payments, cart redirect behavior, login requirements for checkout, and the status of processed bookings. An attacker could redirect the booking flow or disable payments.
The vulnerability requires an account. That makes it less urgent than one exploitable from the outside without authentication. It should still be closed before an attacker combines it with another vulnerability that gives them an account.
Update to version 5.3.8.
- Affected
- Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
- Fixed in
- 5.3.8
- CVSS
- 4.3
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.23 %
percentile 14.2 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
WowStore
CVE-2026-17162Affects you if you run the WowStore plugin in version 4.4.24 or earlier and have registered users with at least a Contributor role.
An attacker with a Contributor account can store malicious script in a block attribute. The script runs whenever someone visits the affected page. On its own this is annoying but not earth-shattering, because the attacker needs an account. Combined with another vulnerability that provides one, it becomes an effective attack on every visitor to the site.
Update to version 4.5.0. The source does not name a workaround.
- Affected
- WowStore – Store Builder & Product Blocks for WooCommerce
- Fixed in
- 4.5.0
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.19 %
percentile 9.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
WowStore – Store Builder & Product Blocks for WooCommerce
CVE-2026-17161Affects you if you run the WowStore plugin in a version up to 4.4.24 and users with the Contributor role or higher have access to the editor.
Stored XSS via a block attribute. An authenticated user with at least Contributor privileges can place scripts in the editor that execute in the browser of other visitors when the page is loaded. The save-time sanitization fails because the payload sits inside a JSON comment within a Gutenberg delimiter block and survives that way.
The attacker needs an account but does not need to be an administrator. That makes the vulnerability relevant in multi-user environments, such as shops with external product maintainers.
Update to version 4.5.0. The source does not name a workaround.
- Affected
- WowStore – Store Builder & Product Blocks for WooCommerce
- Fixed in
- 4.5.0
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.19 %
percentile 9.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Contact Form to Any API
CVE-2026-15735Affects you if you run the Contact Form to Any API plugin in versions up to and including 3.0.6 and your installation has users with the Contributor role or higher that you do not fully control.
An attacker with a Contributor account can store malicious scripts in the plugin's post meta data. These scripts execute whenever someone accesses the affected page. The attacker needs an account for this, but no administrator privileges. The vulnerability is not listed in the KEV catalog of actively exploited flaws, and the likelihood of widespread exploitation is low at an EPSS of 0.2 %.
On its own, this is a finding that requires an existing account. In an environment where you do not give the Contributor role to strangers, the risk is manageable. If you do, you should act.
Update to version 3.0.7.
- Affected
- Contact Form to Any API
- Fixed in
- 3.0.7
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.19 %
percentile 9.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
AffiliateWP
CVE-2026-65515Affects you if you run AffiliateWP up to and including version 2.35.0.
Stored cross-site scripting exploitable without authentication. An attacker can place malicious code in your installation that executes in your visitors' browsers. The plugin is widely deployed and the vulnerability reachable from the outside.
Update to version 2.35.1.
- Affected
- AffiliateWP
- Fixed in
- 2.35.1
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.