Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Icegram Engage
CVE-2026-16087Affects you if you run Icegram Engage in versions up to and including 3.1.42 and have registered users with at least the Contributor role.
A SQL injection that works in two steps. An attacker with a Contributor account or higher stores a crafted value that initially looks harmless. During a later database query, that value is inserted into a SQL statement without checking and gets executed. This allows the attacker to read the database.
The vulnerability requires an account, but Contributor is the lowest writing role in WordPress. Many installations hand it out to guests or customers. That makes the hole relevant for those systems.
Update to the version that Wordfence lists as fixed. The source does not name a specific version number.
- Affected
- Icegram Engage – Popups, Optins, CTAs & Lead Generation
- Fixed in
- 3.1.43
- CVSS
- 6.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.27 %
percentile 18.9 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
GSheetConnector
CVE-2026-16614Affects you if you run the GSheetConnector plugin in version 5.2.1 or older and an attacker has access to an administrator account.
A SQL injection in the administration interface. An attacker with administrator privileges can append their own database commands to existing queries via the 's' parameter, extracting sensitive information from the database. The damage is limited to what an administrator could already see or export.
The vulnerability exists because wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters. Single quotes and other metacharacters remain in the parameter and become part of the query.
Update to version 5.2.2.
- Affected
- GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database
- Fixed in
- 5.2.2
- CVSS
- 4.9
source security@wordfence.com - Login required
- yes, administrator
- Likely to be exploited
- 0.27 %
percentile 18.7 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Download Manager
CVE-2026-16685Affects you if you run the Download Manager plugin in a version up to and including 3.3.66 and have at least one user with the Contributor role or higher.
An attacker with a Contributor account can store a script in a shortcode attribute. The plugin sanitizes the post content on save, but not the shortcode attribute values. When the page is loaded, the script executes in the browser of other visitors, including administrators. The attacker needs an account, but not a highly privileged one.
Update to version 3.3.67. The source does not mention another workaround.
- Affected
- Download Manager
- Fixed in
- 3.3.67
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.24 %
percentile 15.4 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Advanced Woo Labels
CVE-2026-15662Affects you if you run Advanced Woo Labels up to and including version 2.48 and have users with the Contributor role or higher.
An attacker with a Contributor account can store malicious code in the database via the bg_color parameter. The code runs in the browser of every visitor who opens the affected page. On its own this is annoying but not critical, because the attacker already needs an account.
The vulnerability is not on the KEV catalog of actively exploited vulnerabilities. That matches the low EPSS of 0.2 percent. I rate it for awareness, because a Contributor account is the hurdle and no active mass exploitation is known.
Update to version 2.49.
- Affected
- Advanced Woo Labels – Product Labels & Badges for WooCommerce
- Fixed in
- 2.49
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.24 %
percentile 14.5 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
AI Engine – The Chatbot, AI Framework & MCP for WordPress
CVE-2026-15988Affects you if you run the AI Engine plugin in versions up to and including 3.6.5.
An attacker can trick an administrator of your site into clicking a crafted link. If they do, a new administrator account with attacker-supplied credentials is created without their knowledge. The vulnerability exists because a security check, the nonce, is missing from a specific function. On its own, this is a classic Cross-Site Request Forgery. Combined with how WordPress processes REST requests, it becomes full privilege escalation.
The attack requires an action by the administrator. That makes it less likely than a vulnerability requiring no interaction, but not harmless. A targeted link in a seemingly legitimate email is enough.
Update the plugin to version 3.6.6. Then check your user list for unknown administrator accounts.
- Affected
- AI Engine – The Chatbot, AI Framework & MCP for WordPress
- Fixed in
- 3.6.6
- CVSS
- 8.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.22 %
percentile 12.3 - Type
- CWE-352
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Fluent Forms
CVE-2026-17571Affects you if you run Fluent Forms up to and including 6.2.8.
An attacker can place malicious code in the display if they can trick someone into clicking a crafted link. No login is required. The attack is limited to the browser of the person who clicks and runs in the context of your own site. That makes it less sweeping than a vulnerability that works without interaction, but it is not harmless.
Update to 6.2.9.
- Affected
- Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Fixed in
- 6.2.9
- CVSS
- 6.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.21 %
percentile 11.5 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Powerkit
CVE-2026-15644Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and your WordPress site has users with the Contributor role or higher.
An attacker with a Contributor account can plant malicious scripts on a page via the 'style' shortcode attribute. When another user visits that page, the script executes in their browser. That is enough to hijack sessions or trick administrators into actions they did not intend.
The vulnerability is not on the KEV catalog of actively exploited flaws. It requires an account, but the bar is low: Contributor is the role you give a guest author so they can submit a draft.
Update Powerkit to version 3.1.1.
- Affected
- Powerkit – Supercharge your WordPress Site
- Fixed in
- 3.1.1
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 10.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Powerkit
CVE-2026-15645Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and people with the Contributor role or higher have access to your site.
An attacker with an account of at least the Contributor role can place a script via the nav shortcode attribute. The script executes in the browser of every visitor who loads a page containing that shortcode. The damage depends on what the attacker does with the script, but the door is open.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. That is a snapshot, not a guarantee that it is not being exploited somewhere.
Update Powerkit to version 3.1.1.
- Affected
- Powerkit – Supercharge your WordPress Site
- Fixed in
- 3.1.1
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 10.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Kadence Blocks
CVE-2026-18062Affects you if you run Kadence Blocks up to and including 3.7.8.1 and allow users with contributor-level access or higher to create posts.
A stored cross-site scripting vulnerability in the Identity Block. An attacker with contributor access can place scripts that execute whenever someone visits the page. The attack requires the urlTransparent attribute to be set on the block. Without that value, the vulnerable code path is never reached.
The hole is not exploitable from the outside, but contributor accounts are common in editorial teams and multi-user client projects. Kadence Blocks is widely deployed, so I am including it.
Update Kadence Blocks to 3.7.8.2.
- Affected
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Fixed in
- 3.7.8.2
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 10.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
SureForms
CVE-2026-7623Affects you if you run the SureForms plugin in versions up to and including 2.8.1 on your WordPress site and users with the Contributor role or higher exist.
Stored cross-site scripting via a block attribute. An attacker with a Contributor account can plant scripts that execute whenever someone visits the page. The hurdle is the account, but the Contributor role is often handed to guest authors without the same scrutiny as an administrator.
Update to version 2.8.2.
- Affected
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
- Fixed in
- 2.8.2
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.21 %
percentile 10.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
345 checked and dismissed, with reasons
- 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesKein Java-Anwendungsserver im Bestand.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
- CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
- CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
- CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
- CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
- CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
- CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
- CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
- CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
- CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
- CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
- CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
- CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
- CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.