Threat Log

626advisories read
281affect you
345checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 281 entries
  1. For the record Wordfence

    Independent Analytics

    CVE-2026-17506

    Affects you if you run the Independent Analytics plugin in a version up to and including 2.15.0.

    An attacker can store malicious code in the analytics data without logging in. The code executes as soon as someone with the right permissions views the 404 statistics in the dashboard. The plugin sanitizes the submitted URLs in the wrong order, so a harmless-looking address turns into active HTML when displayed.

    Update to version 2.15.1.

    Affected
    Independent Analytics – WordPress Analytics Plugin
    Fixed in
    2.15.1
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 13.9
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    JS Help Desk – AI-Powered Support & Ticketing System

    CVE-2026-14928

    Affects you if you run the JS Help Desk plugin below version 3.1.4 and have registered users, even at the lowest role.

    The plugin does not check whether the requesting user owns a ticket before displaying its content. Any authenticated user, even with the Subscriber role, can read the subject and full message body of other users' tickets. This is a clear breach of confidentiality for the communication between your customers and your support team.

    The vulnerability is not on the KEV list of actively exploited flaws. The likelihood of exploitation is low, with an EPSS of 0.2 %, but the impact on user trust in a support system is high.

    Update to version 3.1.4.

    Affected
    JS Help Desk – AI-Powered Support & Ticketing System
    Fixed in
    3.1.4
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 12.5
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Events Manager – Calendar, Bookings, Tickets, and more!

    CVE-2026-66457

    Affects you if you run the Events Manager plugin in a version up to and including 7.4.2.

    An attacker can inject malicious scripts into pages provided by the plugin without logging in. These scripts execute whenever someone accesses the affected page. The source does not name a version that fixes this.

    Check whether an update is available and apply it. If none is available, deactivate the plugin until an update is released.

    Affected
    Events Manager – Calendar, Bookings, Tickets, and more!
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 9.0
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Media Library Assistant

    CVE-2026-61963

    Affects you if you run the Media Library Assistant plugin in a version up to and including 3.38.

    A stored XSS that can be triggered without logging in. An attacker can place scripts that execute whenever someone accesses the affected page. The plugin is widely used, and the fix is available.

    Update to version 3.39.

    Affected
    Media Library Assistant
    Fixed in
    3.39
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Ninja Tables – Easy Data Table Builder

    CVE-2026-61964

    Affects you if you run the WordPress plugin Ninja Tables in a version up to and including 5.2.9.

    An unauthenticated attacker can inject scripts into tables that execute in the browser of other visitors when the page is loaded. The plugin does not sufficiently sanitize input and outputs it unchanged. A classic stored XSS.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. A fix is available.

    Update to version 5.2.10.

    Affected
    Ninja Tables – Easy Data Table Builder
    Fixed in
    5.2.10
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    WP Go Maps

    CVE-2026-15381

    Affects you if you run the WP Go Maps plugin in a version below 10.1.04.

    A SQL injection that works without logging in. An attacker can append their own queries to an existing database query and extract information from the database.

    The CVSS score of 3.7 does not reflect this. I rate it higher because it works without credentials and targets a customer's database.

    Update to version 10.1.04.

    Affected
    WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
    Fixed in
    10.1.04
    CVSS
    3.7
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.6
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    NewStatPress

    CVE-2026-14845

    Affects you if you run the NewStatPress WordPress plugin in a version below 1.4.5.

    An attacker can inject data into the statistics without logging in, which then executes in the browser of another visitor when a widget is viewed. This is stored cross-site scripting. It hits anyone who sees the affected widget, not the operator directly.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws.

    Update to version 1.4.5.

    Affected
    NewStatPress
    Fixed in
    1.4.5
    CVSS
    6.1
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.16 %
    percentile 5.9
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Academy LMS

    CVE-2026-12376

    Affects you if you run the Academy LMS WordPress plugin in a version up to and including 3.8.2 and have enrolled users with subscriber-level access or higher.

    The plugin exposes every user's quiz attempts. An attacker with subscriber rights who is enrolled in any single course can view the attempts of every other user. This reveals IP addresses, names, registration dates, and quiz results.

    The vulnerability is not on the CISA KEV list of actively exploited flaws. The CVSS score of 4.3 reflects that an attacker already needs a subscriber account and a course enrollment. For a public learning platform with many enrolled users, that is a low bar.

    The source does not name a fixed version or a workaround. Deactivate the plugin until an update appears, or restrict course enrollments to trusted users.

    Affected
    Academy LMS
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.8
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Clearfy Cache

    CVE-2026-16295

    Affects you if you run Clearfy Cache below version 2.4.3 and have authenticated users with subscriber-level access or above.

    An admin-page dispatch path in the plugin does not check whether the user has the required capabilities. This allows an attacker with a subscriber-level account or higher to access pages intended for administrators only and view their contents, including administrative nonces. The canonical page URL correctly restricts access; the dispatch path does not.

    The source does not mention any ability to modify the displayed data. This is about the disclosure of sensitive information.

    Update to version 2.4.3.

    Affected
    Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
    Fixed in
    2.4.3
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.8
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Remote API

    CVE-2026-14602

    Affects you if you run the Remote API WordPress plugin in version 0.2 or older.

    The plugin accepts data from the outside and processes it without checking authentication first. An attacker can inject a PHP object. On its own, the plugin has no known chain to cause harm. But if another plugin or theme provides such a chain, the attacker can delete files, retrieve sensitive data, or execute code.

    This vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Remove or deactivate the plugin until a fixed version appears. The source does not name a patched release.

    Affected
    Remote API
    CVSS
    9.0
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.52 %
    percentile 41.8
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

345 checked and dismissed, with reasons
  • 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
  • CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.