Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Independent Analytics
CVE-2026-17506Affects you if you run the Independent Analytics plugin in a version up to and including 2.15.0.
An attacker can store malicious code in the analytics data without logging in. The code executes as soon as someone with the right permissions views the 404 statistics in the dashboard. The plugin sanitizes the submitted URLs in the wrong order, so a harmless-looking address turns into active HTML when displayed.
Update to version 2.15.1.
- Affected
- Independent Analytics – WordPress Analytics Plugin
- Fixed in
- 2.15.1
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.23 %
percentile 13.9 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
JS Help Desk – AI-Powered Support & Ticketing System
CVE-2026-14928Affects you if you run the JS Help Desk plugin below version 3.1.4 and have registered users, even at the lowest role.
The plugin does not check whether the requesting user owns a ticket before displaying its content. Any authenticated user, even with the Subscriber role, can read the subject and full message body of other users' tickets. This is a clear breach of confidentiality for the communication between your customers and your support team.
The vulnerability is not on the KEV list of actively exploited flaws. The likelihood of exploitation is low, with an EPSS of 0.2 %, but the impact on user trust in a support system is high.
Update to version 3.1.4.
- Affected
- JS Help Desk – AI-Powered Support & Ticketing System
- Fixed in
- 3.1.4
- CVSS
- 6.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.22 %
percentile 12.5 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Events Manager – Calendar, Bookings, Tickets, and more!
CVE-2026-66457Affects you if you run the Events Manager plugin in a version up to and including 7.4.2.
An attacker can inject malicious scripts into pages provided by the plugin without logging in. These scripts execute whenever someone accesses the affected page. The source does not name a version that fixes this.
Check whether an update is available and apply it. If none is available, deactivate the plugin until an update is released.
- Affected
- Events Manager – Calendar, Bookings, Tickets, and more!
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 9.0 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Media Library Assistant
CVE-2026-61963Affects you if you run the Media Library Assistant plugin in a version up to and including 3.38.
A stored XSS that can be triggered without logging in. An attacker can place scripts that execute whenever someone accesses the affected page. The plugin is widely used, and the fix is available.
Update to version 3.39.
- Affected
- Media Library Assistant
- Fixed in
- 3.39
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Ninja Tables – Easy Data Table Builder
CVE-2026-61964Affects you if you run the WordPress plugin Ninja Tables in a version up to and including 5.2.9.
An unauthenticated attacker can inject scripts into tables that execute in the browser of other visitors when the page is loaded. The plugin does not sufficiently sanitize input and outputs it unchanged. A classic stored XSS.
The vulnerability is not listed in the KEV catalog of actively exploited flaws. A fix is available.
Update to version 5.2.10.
- Affected
- Ninja Tables – Easy Data Table Builder
- Fixed in
- 5.2.10
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
WP Go Maps
CVE-2026-15381Affects you if you run the WP Go Maps plugin in a version below 10.1.04.
A SQL injection that works without logging in. An attacker can append their own queries to an existing database query and extract information from the database.
The CVSS score of 3.7 does not reflect this. I rate it higher because it works without credentials and targets a customer's database.
Update to version 10.1.04.
- Affected
- WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
- Fixed in
- 10.1.04
- CVSS
- 3.7
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.6 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
NewStatPress
CVE-2026-14845Affects you if you run the NewStatPress WordPress plugin in a version below 1.4.5.
An attacker can inject data into the statistics without logging in, which then executes in the browser of another visitor when a widget is viewed. This is stored cross-site scripting. It hits anyone who sees the affected widget, not the operator directly.
The vulnerability is not listed in the KEV catalog of actively exploited flaws.
Update to version 1.4.5.
- Affected
- NewStatPress
- Fixed in
- 1.4.5
- CVSS
- 6.1
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.16 %
percentile 5.9 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Academy LMS
CVE-2026-12376Affects you if you run the Academy LMS WordPress plugin in a version up to and including 3.8.2 and have enrolled users with subscriber-level access or higher.
The plugin exposes every user's quiz attempts. An attacker with subscriber rights who is enrolled in any single course can view the attempts of every other user. This reveals IP addresses, names, registration dates, and quiz results.
The vulnerability is not on the CISA KEV list of actively exploited flaws. The CVSS score of 4.3 reflects that an attacker already needs a subscriber account and a course enrollment. For a public learning platform with many enrolled users, that is a low bar.
The source does not name a fixed version or a workaround. Deactivate the plugin until an update appears, or restrict course enrollments to trusted users.
- Affected
- Academy LMS
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.8 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Clearfy Cache
CVE-2026-16295Affects you if you run Clearfy Cache below version 2.4.3 and have authenticated users with subscriber-level access or above.
An admin-page dispatch path in the plugin does not check whether the user has the required capabilities. This allows an attacker with a subscriber-level account or higher to access pages intended for administrators only and view their contents, including administrative nonces. The canonical page URL correctly restricts access; the dispatch path does not.
The source does not mention any ability to modify the displayed data. This is about the disclosure of sensitive information.
Update to version 2.4.3.
- Affected
- Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Fixed in
- 2.4.3
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.8 - Type
- CWE-284
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Remote API
CVE-2026-14602Affects you if you run the Remote API WordPress plugin in version 0.2 or older.
The plugin accepts data from the outside and processes it without checking authentication first. An attacker can inject a PHP object. On its own, the plugin has no known chain to cause harm. But if another plugin or theme provides such a chain, the attacker can delete files, retrieve sensitive data, or execute code.
This vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
Remove or deactivate the plugin until a fixed version appears. The source does not name a patched release.
- Affected
- Remote API
- CVSS
- 9.0
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.52 %
percentile 41.8 - Type
- CWE-94
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
345 checked and dismissed, with reasons
- 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesKein Java-Anwendungsserver im Bestand.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
- CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
- CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
- CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
- CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
- CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
- CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
- CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
- CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
- CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
- CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
- CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.