Threat Log

626advisories read
281affect you
345checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 281 entries
  1. This week Wordfence

    User Profile Picture

    CVE-2026-61971

    Affects you if you use the User Profile Picture plugin in a version up to and including 2.6.3 and your installation has users with the Author role or higher whom you do not fully trust.

    An insecure direct object reference. An authenticated user with at least Author privileges can manipulate the user ID in a request and change another user's profile picture. On its own not a critical intervention, but an unwanted access to someone else's data that should not happen in a multi-author environment.

    Update to version 2.6.4.

    Affected
    User Profile Picture
    Fixed in
    2.6.4
    CVSS
    2.7
    source audit@patchstack.com
    Login required
    yes, administrator
    Likely to be exploited
    0.19 %
    percentile 9.1
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    Auto Featured Image (Auto Post Thumbnail)

    CVE-2026-61970

    Affects you if you run the Auto Featured Image plugin in a version up to and including 5.0.4 and have users with the Contributor role or higher.

    An attacker with a Contributor account can make the plugin send requests to internal services that are not reachable from the outside. That is enough to map the infrastructure behind the website or to talk to other unpatched services. On its own, the vulnerability relies on the reach of a restricted account, hence the rating for this week.

    Update to version 5.0.5. The source does not name a workaround.

    Affected
    Auto Featured Image (Auto Post Thumbnail)
    Fixed in
    5.0.5
    CVSS
    4.9
    source audit@patchstack.com
    Login required
    yes, user account
    Likely to be exploited
    0.12 %
    percentile 2.1
    Type
    CWE-918
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Kirki

    CVE-2026-15601

    Affects you if you run the Kirki plugin in a version up to and including 6.0.13 and a user with Editor privileges or higher exists.

    A path traversal via crafted ZIP files. An attacker with an account at Editor level or above can twist paths when extracting archives so that files end up outside the intended directory. This allows writing an arbitrary file on the server, which in the next step enables code execution.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. The CVSS of 4.9 reflects the hurdle that an attacker already needs an account with write access.

    Update Kirki to version 6.1.0.

    Affected
    Kirki – Freeform Page Builder, Website Builder & Customizer
    Fixed in
    6.1.0
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.77 %
    percentile 52.3
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Kali Forms

    CVE-2026-16144

    Affects you if you run the Kali Forms plugin in any version up to and including 2.4.20 and at least one form contains a field named thisPermalink, entryCounter, or submission_link. You can check that in the form editor.

    An attacker can execute their own code on your server without logging in. All it takes is submitting a form that contains one of the reserved fields. The plugin's own safeguard only checks whether the placeholders have changed, not whether they come from the outside. A trusted call is fed with attacker data.

    The vulnerability is not on the KEV list and the EPSS likelihood sits at 0.7 percent. That argues against widespread exploitation. Still, act now: if you run a form with the named fields, you have an open door on your system.

    Update to version 2.4.21. The source names no workaround that avoids the update.

    Affected
    Kali Forms — Contact Form & Drag-and-Drop Builder
    Fixed in
    2.4.21
    CVSS
    8.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.69 %
    percentile 49.5
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Single Sign On For TNG

    CVE-2026-15964

    Affects you if you run the WordPress plugin Single Sign On For TNG in any version up to and including 2.0.0.

    A plugin that lets people skip the login. A stranger can reset the password of any user without credentials and then sign in as that user, administrator included. The function that does this is reachable without authentication and does not check whether the request comes from the legitimate account owner.

    Update to the next available version that closes this hole. If none exists yet, disable the plugin until the update ships.

    Affected
    Single Sign On For TNG
    Fixed in
    2.1.0
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.49 %
    percentile 39.7
    Type
    CWE-620
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Subscriptions for WooCommerce

    CVE-2026-15414

    Affects you if you run Subscriptions for WooCommerce up to and including version 2.0.0 and users with the Contributor role or higher have backend access.

    A Contributor can promote themselves to Administrator. The plugin saves a user role from the form when editing a membership plan, without checking whether the sender is allowed to assign that role. The only restriction in the form is a grayed-out field that can be overwritten using the browser's developer tools. The server accepts the value and writes it to the database.

    Update to a version that closes this vulnerability. If no update is available, check the user list for administrators you did not create.

    Affected
    Subscriptions for WooCommerce
    Fixed in
    2.0.1
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.34 %
    percentile 26.3
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    PixelYourSite

    CVE-2026-18059

    Affects you if you run PixelYourSite up to 11.2.1 in a WooCommerce shop and the order received page is reachable, whether visitors are logged in or not.

    The plugin writes sensitive order data into the page source of the order received page as soon as it sees an order ID in the URL. It does not check whether the visitor actually owns that order. An attacker can cycle through order IDs and pull product names, quantities, per-item prices, order totals, and transaction IDs.

    No account is required. The hole is exploitable remotely with nothing more than a guessable or enumerated order ID.

    Update to 11.2.2 or 12.6.1. The source provides no workaround that replaces taking the order received page offline.

    Affected
    PixelYourSite Pro – Your smart PIXEL (TAG) Manager, PixelYourSite – Your smart PIXEL (TAG) & API Manager
    Fixed in
    11.2.2, 12.6.1
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 25.9
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Pronamic Pay

    CVE-2026-16635

    Affects you if you run Pronamic Pay up to and including version 10.1.0 and use Gravity Forms with a user role update field. An attacker needs an account, even just a subscriber account.

    An attacker with a basic account can make themselves an administrator. The function that sets the role does not check which roles are allowed. It takes the value from the form and writes it directly into the user record. An administrator must have set up the Gravity Forms connection beforehand, otherwise the vulnerability leads nowhere.

    The vulnerability is not on the KEV list and the likelihood of exploitation is 0.3 percent. It is still here because it applies to my systems and an attacker gains administrator rights with a single form submission.

    Update to version 10.2.0. The source names no workaround; only the update helps.

    Affected
    Pronamic Pay
    Fixed in
    10.2.0
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.31 %
    percentile 23.4
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    CubeWP Framework

    CVE-2026-6453

    Affects you if you run the WordPress plugin CubeWP Framework up to version 1.1.30 and an attacker has an account with subscriber-level access or higher.

    A SQL injection in the AJAX function cubewp_remove_relation(). The relation_id parameter is interpolated directly into a SQL query without sufficient sanitization. An attacker with an account that has at least subscriber rights can send their own SQL commands to the database.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 1.1.31.

    Affected
    CubeWP Framework
    Fixed in
    1.1.31
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.28 %
    percentile 20.5
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    W3 Total Cache

    CVE-2026-66695

    Affects you if you run W3 Total Cache in a version up to and including 2.10.2. The vulnerability is triggerable without authentication.

    A path traversal that works without logging in. An attacker can access files outside the intended directory, including configuration files with credentials or other sensitive content. W3 Total Cache is widely deployed, so the attack surface is large.

    Update to version 2.10.3. The source does not name a workaround.

    Affected
    W3 Total Cache
    Fixed in
    2.10.3
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 19.4
    Type
    CWE-35
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

345 checked and dismissed, with reasons
  • 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
  • CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.