Threat Log
Nothing on this page matches that search. Have a look at the other pages.
-
This week BSI CERT-Bund
WordPress Core
CVE-2026-64638Affects you if you run WordPress. Out of the box, that is the case.
A reflected XSS vulnerability on the login screen, exploited without an account. An attacker has to lure a victim to a prepared page and prompt an action. If that succeeds, the flaw can escalate to code execution on the server. The condition for that is not in the attacker's hands, but in the victim's.
The flaw affects all versions. Chaining is common with WordPress, so it is here despite a middling exploitation value.
Update to 7.0.3 or the backport for your version from 4.7 onward.
- Affected
- WordPress
- CVSS
- 8.9
source support@hackerone.com - Login required
- no
- Likely to be exploited
- 0.77 %
percentile 52.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · BSI CERT-Bund
-
This week Wordfence
Page and Post Restriction
CVE-2026-12000Affects you if you use the Page and Post Restriction plugin to make content visible only to logged-in users.
The plugin is supposed to lock pages and posts so only logged-in users can see them. But the WordPress REST API pulls the lock list from the wrong settings and misses the global toggles. Anyone who knows the REST endpoints reads the locked content without logging in.
The flaw only affects reading. An attacker gains no privileges, but can see privacy-relevant data that was meant to stay behind a login.
Update to the latest version of the plugin. Until then, you can block the REST API for unauthenticated users if your content requires it.
- Affected
- Page and Post Restriction
- Fixed in
- 1.4.2
- CVSS
- 7.5
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.66 %
percentile 48.2 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week BSI CERT-Bund
Redis
CVE-2026-66373Affects you if you run Redis as an object cache for WordPress and the service is reachable from the network.
Remote code execution that requires an authenticated attacker. That sounds like a hard condition, but Redis is widely used as an object cache in WordPress environments and often runs without its own network isolation. Whoever reaches the service often has half the work done.
The flaw sits in the RESTORE command and leads to a double free. The vendor has released the update to 8.8.0.
Update to 8.8.0. If that is not possible right away, make sure Redis is only reachable from the local network and the RESTORE command cannot be used from outside.
- Affected
- Redis
- CVSS
- 7.5
source cve@mitre.org - Login required
- yes, user account
- Likely to be exploited
- 0.50 %
percentile 40.3 - Type
- CWE-415
- Actively exploited
- not on the KEV list
- Published
- 2026-08-07
Sources: NVD · EPSS · BSI CERT-Bund
-
This week Wordfence
Wholesale for WooCommerce
CVE-2026-12144Affects you if you use the Wholesale for WooCommerce plugin and give editors with author-level or higher roles access to the backend.
A privilege escalation within WordPress. An editor with author-level rights can assign themselves new roles through an unprotected parameter, up to administrator. The flaw is the missing check on which roles are allowed and whether the user has the capability to assign roles.
For shops with a single operator and no additional editors, the risk is low. As soon as multiple people maintain content, an editor becomes a full administrator with a single click.
Update the plugin to the latest version and review the user roles in the backend to see whether anyone gained permissions that were not intended.
- Affected
- Wholesale for WooCommerce
- Fixed in
- 2.0.6
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.37 %
percentile 29.6 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-07-28
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week BSI CERT-Bund
OpenSSL
CVE-2026-54876Affects you if you run OpenSSL and operate TLS clients with OCSP checking enabled that connect to servers you do not control.
A malicious TLS server can push a client with OCSP checking enabled into a memory leak through a deliberately empty OCSP response. Each TLS connection leaks an attacker-controlled amount of memory. A client that repeatedly connects to such a server eventually fills up and stops.
This is a denial of service without login, from outside, over a path every TLS client takes. OpenSSL sits under everything. The condition is OCSP checking being enabled, not the installation itself.
Update OpenSSL to the latest version. Check whether your clients have OCSP checking enabled and switch it off where it is not needed.
- Affected
- OpenSSL
- CVSS
- 7.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.26 %
percentile 17.7 - Type
- CWE-401
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · BSI CERT-Bund
-
This week Wordfence
WooCommerce PayPal Payments
CVE-2025-14073Affects you if you run WooCommerce PayPal Payments in versions up to 3.3.2 and process customer orders via PayPal.
A vulnerability that allows anyone without login to retrieve order data within 10 minutes of order placement. The attacker guesses or obtains an order key and uses it to access full customer details such as name, email, phone, and address via the Store API.
The time window is narrow, but the data is sensitive. An automated attack could query many orders within this window.
Update to the latest version of the plugin and check whether your Store API restricts access from outside.
- Affected
- WooCommerce PayPal Payments
- Fixed in
- 3.4.0
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.23 %
percentile 14.1 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
PDFDraft
CVE-2026-12124Affects you if you use the PDFDraft plugin and have stored templates for invoices, certificates, or similar documents with customer data in it.
The plugin does not check on two paths whether someone is authorized to download a PDF template. Anyone who knows or guesses a template identifier can retrieve the finished document without logging in. It may contain names, invoice and order data, or other personal information of your customers.
The vulnerability is not hard to exploit, but it requires that templates with sensitive content exist in the first place. If they do, this is not a technical toy, but a data protection incident.
Update to the latest version of the plugin. If none is available, disable the plugin until an update is released.
- Affected
- PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
- Fixed in
- 1.1.1
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.21 %
percentile 11.2 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-07-27
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
FormGent Form Builder
CVE-2025-15028Affects you if you run the FormGent plugin in version 1.9.2 or older and your forms are publicly accessible.
A stored XSS vulnerability in a form builder plugin. Unauthenticated attackers can inject scripts through form fields that execute when the stored page is viewed. If an administrator hits the page, this can lead to account takeover.
The plugin is widely used and the flaw requires no login. Exploitation is not complex, but the EPSS score is low, suggesting no active exploitation.
Update to the latest version of the plugin. If an update is not possible, temporarily disable the plugin.
- Affected
- FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
- Fixed in
- 1.10.0
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 8.9 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Fluent Forms
CVE-2026-11881Affects you if you run Fluent Forms before 6.2.6 and allow users with the Contributor role or similar to manage forms.
A stored XSS vulnerability in a form field. A contributor can write scripts into the form configuration that run in the browser of any visitor who loads the form, including administrators.
The plugin is widely used, but the vulnerability requires an account with at least the Contributor role. Anyone who does not grant this role to strangers has a lower risk.
Update to 6.2.6 or later.
- Affected
- Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Fixed in
- 6.2.6
- CVSS
- 6.1
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-30
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record BSI CERT-Bund
libpng
CVE-2026-33416 and 1 moreAffects you if your WordPress installation processes image uploads and the underlying PNG library is not up to date.
Two vulnerabilities in the PNG library that share a heap-allocated buffer between two structures with independent lifetimes when setting transparency and palette data. That is a classic use-after-free pattern. An uploaded image can trigger the flaw.
Exploitation is not active. It requires specific call patterns that are not present in the standard case. The flaw is still a path to code execution via an uploaded file.
Update the library to the latest version. If no update is available, removing the affected version from the processing path is the only option.
- Affected
- libpng
- CVSS
- 7.5
source security-advisories@github.com - Login required
- no
- Likely to be exploited
- 1.05 %
percentile 61.1 - Type
- CWE-416
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · BSI CERT-Bund
583 checked and dismissed, with reasons
- 167 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 9 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 8 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 5 advisoriesKein Java-Anwendungsserver im Bestand.
- 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 1 advisoriesAndere Redaktionssysteme. Ich betreue WordPress.
- CVE-2026-5358CVE wurde als REJECTED eingestuft, da die betroffene NIS+-API in Linux-Distributionen nie ausgeliefert wurde und keine Vertrauensgrenze überschritten wird.
- CVE-2026-1933Samba wird in Georges Stack nicht betrieben und erfordert zudem authentifizierte Nutzer mit Dateisystem-Schreibrechten auf Read-Only-Shares.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-Pointer-Bug im Mailbox-Subsystem für spezifische Hardware, setzt lokale Anwesenheit voraus und hat keine Auswirkungen auf Georges Server-Stack.
- CVE-2025-38554Lokale Use-After-Free im VMA-Management, erfordert lokalen Zugriff und ist nur unter speziellen Race-Conditions ausnutzbar, was auf Georges gehärteten Systemen nicht praktisch relevant ist.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, der ein lokales Konto und ein manipuliertes Dateisystem-Image voraussetzt, was auf Georges Servern nicht zutrifft.
- CVE-2025-40086Lokaler Bug im GPU-DRM-Treiber, betrifft nur spezifische Grafikhardware und ist auf Georges reinen Server-Systemen ohne GPU nicht relevant.
- CVE-2025-40178Lokaler NULL-Pointer-Dereferenz im PID-Subsystem, setzt lokalen Codezugriff voraus und führt nur zu einem Kernel-Panic, ohne Datenabfluss.
- CVE-2018-1000204Alter SG_IO-ioctl-Bug von 2018, der CAP_SYS_ADMIN und CAP_SYS_RAWIO erfordert und von Dritten als nicht relevant eingestuft wird.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem beim Laden korrupter Inodes von Disk, setzt lokalen Zugriff und ein manipuliertes Image voraus.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debugging, betrifft nur Systeme mit aktiviertem CONFIG_DEBUG_STACK_USAGE und führt zu fehlerhaften Stack-Statistiken.
- CVE-2025-71200Lokaler Bug im MMC-SDHCI-Treiber für Rockchip-Hardware, betrifft spezifische Embedded-Hardware und ist auf Georges Servern ohne solche Komponenten nicht relevant.
- CVE-2025-71225Lokaler Bug im MD-RAID-Subsystem, der nur bei aktiven RAID-Reshape-Operationen unter I/O-Fehlern auftritt und lokalen Zugriff voraussetzt.
- CVE-2026-31535Lokaler Race-Condition-Bug im SMB-Client, der nur bei SMBDirect-Verbindungen auftritt, was auf Georges Servern nicht eingesetzt wird.
- CVE-2026-23234Lokaler Use-After-Free im f2fs-Dateisystem, der ein lokales Konto und eine Race-Condition zwischen Loop-Device und Unmount voraussetzt.
- CVE-2026-46300Fragnesia genannte Kernel-Lücke ist eine lokale Rechteausweitung, die ein bestehendes Konto auf der Maschine voraussetzt, was auf Georges gehärteten Systemen nicht zutrifft.
- CVE-2026-32792Unbound DNSCrypt-DoS-Lücke betrifft nur Systeme, die explizit mit DNSCrypt-Support kompiliert wurden, was in Georges Stack nicht vorkommt.
- CVE-2026-43495Lokaler Out-of-Bounds-Read im t7xx-WWAN-Treiber, der ein manipuliertes Modem voraussetzt und spezifische Hardware betrifft, die in Georges Server-Stack nicht vorkommt.
- CVE-2025-37780Lokaler Out-of-Bounds-Read im isofs-Dateisystem, der ein manipuliertes Datei-Handle von lokaler Seite voraussetzt und nur auf Systemen mit ISO-Dateisystem relevant ist.
- CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, der nur bei spezifischer Embedded-Hardware mit Speicherzuweisungsfehlern auftritt und keine Auswirkungen auf Georges Server hat.
- CVE-2026-46316KVM arm64-Lokalrechteausweitung, die auf Georges Debian/Ubuntu-Servern ohne ARM-Hardware und ohne lokale Angreifer nicht relevant ist.
- CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Stack des Kernels, die ein Konto auf der Maschine voraussetzt und nicht aktiv ausgenutzt wird.
- CVE-2026-0864CPython-Schwachstelle im configparser-Modul erfordert Kontrolle über geschriebene Werte und betrifft nur das Schreiben von Konfigurationsdateien, nicht den Serverbetrieb.
- CVE-2026-52912Lokale Kernel-Lücke im netfilter-Queue-Handling, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird.
- CVE-2026-52944ksmbd-Lücke betrifft den Kernel-SMB-Server, der auf Georges Servern nicht als Dienst betrieben wird.