Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    Simply Schedule Appointments

    CVE-2026-65513

    Affects you if you run the Simply Schedule Appointments plugin in a version up to and including 1.6.12.10.

    A stranger can place a booking with a malicious script in the calendar, without logging in. The script runs in the browser of another visitor as soon as they open the affected page. Hijacking sessions, reading keystrokes, redirecting to other sites – anything a script is allowed to do in the context of your site is possible.

    Update to version 1.6.12.11.

    Affected
    Simply Schedule Appointments
    Fixed in
    1.6.12.11
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    wpDataTables

    CVE-2026-65509

    Affects you if you run wpDataTables in any version up to and including 7.5.1.

    A stranger can place a message in one of your tables without logging in, and that message runs in the browser of every other visitor who loads the page. That is enough to hijack sessions or redirect the site.

    Update to 7.5.2.

    Affected
    wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
    Fixed in
    7.5.2
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Facturación Electrónica Costa Rica

    CVE-2026-9720

    Affects you if you use the Facturación Electrónica Costa Rica plugin for WordPress in any version up to and including 2.0.2.

    An attacker can change the plugin's configuration, including API tokens, access keys, and invoice settings. To do so, they must trick a site administrator into clicking a crafted link. The vulnerability exists because a security check that normally blocks such forged requests is missing.

    The attack requires an administrator action and is therefore less likely than a direct access. The potential damage from manipulated tokens and settings is real, however.

    No fixed version or workaround is known for this vulnerability. Watch the plugin page for an update and consider deactivating the plugin until then if you do not strictly need its functionality.

    Affected
    Facturación Electrónica Costa Rica
    CVSS
    4.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.13 %
    percentile 2.8
    Type
    CWE-352
    Actively exploited
    not on the KEV list
    Published
    2026-07-28

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. This week Wordfence

    TrueBooker

    CVE-2026-13161

    Affects you if you use the TrueBooker booking plugin and the booking page is publicly reachable.

    A SQL injection in the booking form. The guard that is supposed to prevent this is a nonce, which the booking page exposes in plain text to every visitor. Anyone without credentials simply reads it and bypasses the check.

    The result is access to the database, with no account, no password, from the outside. The likelihood of exploitation is low, but the path there is short.

    Update to the latest version of the plugin. If no updated version is available, disable the plugin until a fix is released.

    Affected
    TrueBooker – Appointment Booking and Scheduler System
    Fixed in
    1.2.3
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 37.2
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. This week Wordfence

    PickPlugins Question Answer

    CVE-2026-10207

    Affects you if you use the PickPlugins Question Answer plugin and the user profile page is reachable from outside.

    A SQL injection via a GET parameter that can be reached without login. An attacker can append additional queries to the database and extract sensitive data. The flaw sits in the user profile output, which is reachable out of the box.

    Exploitation requires no account and no login. Anyone who knows the profile page can manipulate the query.

    Update the plugin to a version after 1.2.73 once the vendor releases a fix. Until then, disable the plugin or block the user profile page for external access.

    Affected
    PickPlugins Question Answer
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 22.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. This week Wordfence

    Premium Packages – Sell Digital Products Securely

    CVE-2026-12800

    Affects you if you run the Premium Packages – Sell Digital Products Securely plugin in version 6.2.0 or earlier and the REST API is reachable from outside.

    An SQL injection via a public REST endpoint of the plugin. An attacker can manipulate database queries without authentication and extract sensitive data from the database.

    The vulnerability is in the coupon endpoint, where user input is passed into a SQL query without proper sanitization. The plugin is common on WordPress installations that sell digital products.

    Update to the latest version of the plugin. If no updated version is available, disable the plugin until a fix is released.

    Affected
    Premium Packages – Sell Digital Products Securely
    Fixed in
    7.0.0
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 22.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. This week Wordfence

    PDFDraft

    CVE-2026-12124

    Affects you if you run the PDFDraft plugin in version 1.1.0 or older and have PDF templates containing customer data, invoices, or order data stored in them.

    A missing capability check on the function that serves PDF templates. Anyone who knows or guesses a template name can download the associated file without logging in. Templates may contain names, invoice, and order data of your customers.

    The flaw is not hard to exploit, but it requires someone to guess or know a template identifier. That lowers the likelihood, but it does not reduce the damage.

    Update to the latest version of the plugin. If that is not possible, disable the plugin until an update is available.

    Affected
    PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
    Fixed in
    1.1.1
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Debian Security

    Exim

    CVE-2026-66140 and 1 more

    Affects you if your server runs Exim as its mail server and it sends mail.

    A mishandling of queue-name arguments allows access to files outside the spool directory. An attacker can use this to gain elevated privileges. The attack requires the mail server to be actively processing messages.

    The source does not name a specific version with the fix. Update Exim to the newest release your distribution provides.

    Affected
    exim4
    CVSS
    8.4
    source cve@mitre.org
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 19.4
    Type
    CWE-24
    Actively exploited
    not on the KEV list
    Published
    2026-07-24

    Sources: NVD · EPSS · Debian DSA

  9. This week Ubuntu Security

    tar

    CVE-2026-5704

    Affects you if you use tar to receive and extract archives from outside and rely on a pre-extraction check.

    A flaw in tar that allows hidden files with arbitrary content to be placed inside an archive. A pre-extraction check does not see these files. An attacker can thus introduce files onto the system unnoticed if they feed you a crafted archive.

    This vulnerability is not on the KEV catalog of actively exploited flaws. It is rated CVSS 5.0 because an attacker first has to trick you into processing their archive. On its own, that is not a direct system compromise. In an environment that automatically accepts backups, it weighs heavier.

    The source does not name a fixed version. Check incoming archives with a tool that fully lists the contents before you point tar at them.

    Affected
    tar
    CVSS
    5.0
    source secalert@redhat.com
    Login required
    yes, user account
    Likely to be exploited
    0.37 %
    percentile 30.1
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-07-22

    Sources: NVD · EPSS · Ubuntu USN

  10. Act now Added manually Exploited in the wild

    WordPress Core (wp2shell)

    CVE-2026-63030 and 1 more

    Affects you if you run WordPress 6.9 or 7.0 and the REST API is reachable from outside. Out of the box, it is.

    A route confusion in the REST API batch endpoint. On its own it would be a blemish. Combined with the SQL injection in CVE-2026-60137 it turns into access to your database, with no account, no password, from the outside, and subsequently code execution on the server.

    Both flaws sit in the core, not in a plugin. That means every installation that has not been updated is affected, regardless of which extensions you use.

    Update to 6.9.5 or 7.0.2. The same update closes both holes. If your installation has not been updated since July 17, do not assume nothing happened. Go and look.

    Affected
    WordPress Core (wp2shell)
    CVSS
    9.8
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    95.60 %
    percentile 99.9
    Type
    CWE-436
    Actively exploited
    KEV since 2026-07-21
    Published
    2026-07-17

    Sources: Sicherheitshinweis · Hersteller · NVD · EPSS · CISA KEV

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.