Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
User Profile Picture
CVE-2026-61971Affects you if you use the User Profile Picture plugin in a version up to and including 2.6.3 and your installation has users with the Author role or higher whom you do not fully trust.
An insecure direct object reference. An authenticated user with at least Author privileges can manipulate the user ID in a request and change another user's profile picture. On its own not a critical intervention, but an unwanted access to someone else's data that should not happen in a multi-author environment.
Update to version 2.6.4.
- Affected
- User Profile Picture
- Fixed in
- 2.6.4
- CVSS
- 2.7
source audit@patchstack.com - Login required
- yes, administrator
- Likely to be exploited
- 0.19 %
percentile 9.1 - Type
- CWE-639
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Auto Featured Image (Auto Post Thumbnail)
CVE-2026-61970Affects you if you run the Auto Featured Image plugin in a version up to and including 5.0.4 and have users with the Contributor role or higher.
An attacker with a Contributor account can make the plugin send requests to internal services that are not reachable from the outside. That is enough to map the infrastructure behind the website or to talk to other unpatched services. On its own, the vulnerability relies on the reach of a restricted account, hence the rating for this week.
Update to version 5.0.5. The source does not name a workaround.
- Affected
- Auto Featured Image (Auto Post Thumbnail)
- Fixed in
- 5.0.5
- CVSS
- 4.9
source audit@patchstack.com - Login required
- yes, user account
- Likely to be exploited
- 0.12 %
percentile 2.1 - Type
- CWE-918
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Kirki
CVE-2026-15601Affects you if you run the Kirki plugin in a version up to and including 6.0.13 and a user with Editor privileges or higher exists.
A path traversal via crafted ZIP files. An attacker with an account at Editor level or above can twist paths when extracting archives so that files end up outside the intended directory. This allows writing an arbitrary file on the server, which in the next step enables code execution.
The vulnerability is not listed in the KEV catalog of actively exploited flaws. The CVSS of 4.9 reflects the hurdle that an attacker already needs an account with write access.
Update Kirki to version 6.1.0.
- Affected
- Kirki – Freeform Page Builder, Website Builder & Customizer
- Fixed in
- 6.1.0
- CVSS
- 4.9
source security@wordfence.com - Login required
- yes, administrator
- Likely to be exploited
- 0.77 %
percentile 52.3 - Type
- CWE-22
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Kali Forms
CVE-2026-16144Affects you if you run the Kali Forms plugin in any version up to and including 2.4.20 and at least one form contains a field named thisPermalink, entryCounter, or submission_link. You can check that in the form editor.
An attacker can execute their own code on your server without logging in. All it takes is submitting a form that contains one of the reserved fields. The plugin's own safeguard only checks whether the placeholders have changed, not whether they come from the outside. A trusted call is fed with attacker data.
The vulnerability is not on the KEV list and the EPSS likelihood sits at 0.7 percent. That argues against widespread exploitation. Still, act now: if you run a form with the named fields, you have an open door on your system.
Update to version 2.4.21. The source names no workaround that avoids the update.
- Affected
- Kali Forms — Contact Form & Drag-and-Drop Builder
- Fixed in
- 2.4.21
- CVSS
- 8.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.69 %
percentile 49.5 - Type
- CWE-94
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Single Sign On For TNG
CVE-2026-15964Affects you if you run the WordPress plugin Single Sign On For TNG in any version up to and including 2.0.0.
A plugin that lets people skip the login. A stranger can reset the password of any user without credentials and then sign in as that user, administrator included. The function that does this is reachable without authentication and does not check whether the request comes from the legitimate account owner.
Update to the next available version that closes this hole. If none exists yet, disable the plugin until the update ships.
- Affected
- Single Sign On For TNG
- Fixed in
- 2.1.0
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.49 %
percentile 39.7 - Type
- CWE-620
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Subscriptions for WooCommerce
CVE-2026-15414Affects you if you run Subscriptions for WooCommerce up to and including version 2.0.0 and users with the Contributor role or higher have backend access.
A Contributor can promote themselves to Administrator. The plugin saves a user role from the form when editing a membership plan, without checking whether the sender is allowed to assign that role. The only restriction in the form is a grayed-out field that can be overwritten using the browser's developer tools. The server accepts the value and writes it to the database.
Update to a version that closes this vulnerability. If no update is available, check the user list for administrators you did not create.
- Affected
- Subscriptions for WooCommerce
- Fixed in
- 2.0.1
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.34 %
percentile 26.3 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
PixelYourSite
CVE-2026-18059Affects you if you run PixelYourSite up to 11.2.1 in a WooCommerce shop and the order received page is reachable, whether visitors are logged in or not.
The plugin writes sensitive order data into the page source of the order received page as soon as it sees an order ID in the URL. It does not check whether the visitor actually owns that order. An attacker can cycle through order IDs and pull product names, quantities, per-item prices, order totals, and transaction IDs.
No account is required. The hole is exploitable remotely with nothing more than a guessable or enumerated order ID.
Update to 11.2.2 or 12.6.1. The source provides no workaround that replaces taking the order received page offline.
- Affected
- PixelYourSite Pro – Your smart PIXEL (TAG) Manager, PixelYourSite – Your smart PIXEL (TAG) & API Manager
- Fixed in
- 11.2.2, 12.6.1
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.33 %
percentile 25.9 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Pronamic Pay
CVE-2026-16635Affects you if you run Pronamic Pay up to and including version 10.1.0 and use Gravity Forms with a user role update field. An attacker needs an account, even just a subscriber account.
An attacker with a basic account can make themselves an administrator. The function that sets the role does not check which roles are allowed. It takes the value from the form and writes it directly into the user record. An administrator must have set up the Gravity Forms connection beforehand, otherwise the vulnerability leads nowhere.
The vulnerability is not on the KEV list and the likelihood of exploitation is 0.3 percent. It is still here because it applies to my systems and an attacker gains administrator rights with a single form submission.
Update to version 10.2.0. The source names no workaround; only the update helps.
- Affected
- Pronamic Pay
- Fixed in
- 10.2.0
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.31 %
percentile 23.4 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
CubeWP Framework
CVE-2026-6453Affects you if you run the WordPress plugin CubeWP Framework up to version 1.1.30 and an attacker has an account with subscriber-level access or higher.
A SQL injection in the AJAX function cubewp_remove_relation(). The relation_id parameter is interpolated directly into a SQL query without sufficient sanitization. An attacker with an account that has at least subscriber rights can send their own SQL commands to the database.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
Update to version 1.1.31.
- Affected
- CubeWP Framework
- Fixed in
- 1.1.31
- CVSS
- 6.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.28 %
percentile 20.5 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
W3 Total Cache
CVE-2026-66695Affects you if you run W3 Total Cache in a version up to and including 2.10.2. The vulnerability is triggerable without authentication.
A path traversal that works without logging in. An attacker can access files outside the intended directory, including configuration files with credentials or other sensitive content. W3 Total Cache is widely deployed, so the attack surface is large.
Update to version 2.10.3. The source does not name a workaround.
- Affected
- W3 Total Cache
- Fixed in
- 2.10.3
- CVSS
- 6.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.27 %
percentile 19.4 - Type
- CWE-35
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
345 checked and dismissed, with reasons
- 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesKein Java-Anwendungsserver im Bestand.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
- CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
- CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
- CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
- CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
- CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
- CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
- CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
- CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
- CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
- CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
- CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.