Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Online Scheduling and Appointment Booking System – Bookly
CVE-2026-13395Affects you if you run Bookly in a version before 27.8 and the booking page is reachable from outside. It is, if you take appointments online.
A SQL injection in the booking flow. A stranger can append parameters to the query without logging in and read the database. Password hashes are the least of what comes out. The flaw is not on the KEV list, but exploitation is simple and the plugin is widely deployed.
Update to version 27.8 or newer. No workaround is known, only the update helps.
- Affected
- Online Scheduling and Appointment Booking System – Bookly
- Fixed in
- 27.8
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.34 %
percentile 26.7 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
MotoPress Hotel Booking
CVE-2026-15235Affects you if you run MotoPress Hotel Booking in a version below 6.0.4 and allow users with low privileges, such as subscribers, to be created on your installation.
An AJAX endpoint in the plugin returns a booking's full customer details without first checking whether the requester is authorized to see them. Any authenticated user, even a subscriber, can retrieve your customers' names, email addresses, phone numbers, and physical addresses. A data leak through the back door that requires no active exploitation, just an account.
The vulnerability is not listed in the CISA KEV catalog of actively exploited vulnerabilities. That does not make it harmless, but there is currently no indication of ongoing attacks.
Update to version 6.0.4.
- Affected
- MotoPress Hotel Booking
- Fixed in
- 6.0.4
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.22 %
percentile 13.2 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
JetEngine
CVE-2026-28082Affects you if you run the JetEngine WordPress plugin in a version up to and including 3.8.13.1.
A stored XSS that can be triggered without authentication. An attacker can inject arbitrary scripts into pages. These scripts execute whenever a user accesses a page injected in this way. The fix is available in version 3.8.13.2.
Update JetEngine to version 3.8.13.2.
- Affected
- JetEngine
- Fixed in
- 3.8.13.2
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Photo Gallery, Sliders, Proofing and Themes
CVE-2026-28141Affects you if you run the NextGEN Gallery plugin in a version up to and including 4.2.3.
A stored XSS that can be triggered without authentication. An attacker can place scripts that execute in the browser of a visitor or administrator as soon as the affected page is loaded. A fix is available as an update.
Update to version 4.2.4.
- Affected
- Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
- Fixed in
- 4.2.4
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
EmbedPress
CVE-2026-61961Affects you if you run the WordPress plugin EmbedPress in a version up to and including 4.5.6.
Stored XSS that can be triggered without logging in. An attacker can inject arbitrary scripts into pages that execute whenever someone accesses the page. The plugin is widespread because it covers many embedding formats, from PDFs to YouTube videos.
The vulnerability is not listed in the KEV catalog of actively exploited flaws.
Update to version 4.6.0.
- Affected
- EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
- Fixed in
- 4.6.0
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Forminator Forms
CVE-2026-28143Affects you if you run the Forminator Forms plugin in a version up to and including 1.56.0.
A stored XSS that can be triggered without authentication. An attacker can inject scripts into pages that execute in the visitor's browser when the page is accessed. The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
Update to version 1.56.1.
- Affected
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder
- Fixed in
- 1.56.1
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.18 %
percentile 7.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Event Booking Manager for WooCommerce
CVE-2026-16062Affects you if you run the Event Booking Manager for WooCommerce plugin in a version below 5.3.7 and have authenticated users with Contributor-level access or above.
The plugin allows authenticated users with Contributor-level access and above to inject PHP objects into event content fields. On its own, the plugin contains no usable POP chain to turn this into a direct attack. If another plugin or theme with such a chain is installed, it could lead to file deletion, data retrieval, or code execution.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
Update to version 5.3.7.
- Affected
- Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
- Fixed in
- 5.3.7
- CVSS
- 6.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, administrator
- Likely to be exploited
- 0.35 %
percentile 28.0 - Type
- CWE-502
- Actively exploited
- not on the KEV list
- Published
- 2026-08-02
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Element Pack Addons for Elementor
CVE-2026-14817Affects you if you run Element Pack Addons for Elementor in a version below 8.7.13 and have users with the Contributor role or higher.
A stored cross-site scripting vulnerability. An authenticated user with at least Contributor access can inject JavaScript that executes in the browser of any visitor who views the affected page. The flaw exists because the plugin does not sanitize values from certain data attributes before a bundled front-end library re-parses and renders them in the browser.
This vulnerability is not listed in the KEV catalog of actively exploited flaws. Still, schedule the update soon, as the plugin is widely used and an attacker can reach many visitors with a single crafted post.
Update to version 8.7.13.
- Affected
- Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
- Fixed in
- 8.7.13
- CVSS
- 6.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, administrator
- Likely to be exploited
- 0.29 %
percentile 21.4 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-02
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Meta Box
CVE-2026-15248Affects you if you run the Meta Box WordPress plugin in a version below 5.13.1 and have authenticated users with the Contributor role or higher.
An authenticated user with low privileges can permanently delete other users' media attachments. The check for authorization is missing. This is an insecure direct object reference to items they do not own.
The vulnerability is not listed in the KEV catalog of actively exploited flaws. An attacker needs an account, which raises the bar, but the impact on other users' data is direct.
Update to version 5.13.1.
- Affected
- Meta Box
- Fixed in
- 5.13.1
- CVSS
- 5.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, administrator
- Likely to be exploited
- 0.28 %
percentile 20.4 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-02
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Product Attachment for WooCommerce
CVE-2026-16285Affects you if you run the Product Attachment for WooCommerce plugin in a version below 2.3.3.
The plugin does not check whether a requester is authorized when serving media files. An unauthenticated attacker can download any attachment, including private or unlinked files, by guessing its numeric ID.
Update to version 2.3.3.
- Affected
- Product Attachment for WooCommerce
- Fixed in
- 2.3.3
- CVSS
- 7.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.26 %
percentile 18.0 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-02
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
345 checked and dismissed, with reasons
- 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesKein Java-Anwendungsserver im Bestand.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
- CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
- CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
- CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
- CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
- CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
- CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
- CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
- CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
- CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
- CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
- CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.