Threat Log

626advisories read
281affect you
345checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 281 entries
  1. For the record Wordfence

    Icegram Engage

    CVE-2026-16087

    Affects you if you run Icegram Engage in versions up to and including 3.1.42 and have registered users with at least the Contributor role.

    A SQL injection that works in two steps. An attacker with a Contributor account or higher stores a crafted value that initially looks harmless. During a later database query, that value is inserted into a SQL statement without checking and gets executed. This allows the attacker to read the database.

    The vulnerability requires an account, but Contributor is the lowest writing role in WordPress. Many installations hand it out to guests or customers. That makes the hole relevant for those systems.

    Update to the version that Wordfence lists as fixed. The source does not name a specific version number.

    Affected
    Icegram Engage – Popups, Optins, CTAs & Lead Generation
    Fixed in
    3.1.43
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.27 %
    percentile 18.9
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    GSheetConnector

    CVE-2026-16614

    Affects you if you run the GSheetConnector plugin in version 5.2.1 or older and an attacker has access to an administrator account.

    A SQL injection in the administration interface. An attacker with administrator privileges can append their own database commands to existing queries via the 's' parameter, extracting sensitive information from the database. The damage is limited to what an administrator could already see or export.

    The vulnerability exists because wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters. Single quotes and other metacharacters remain in the parameter and become part of the query.

    Update to version 5.2.2.

    Affected
    GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database
    Fixed in
    5.2.2
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.27 %
    percentile 18.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Download Manager

    CVE-2026-16685

    Affects you if you run the Download Manager plugin in a version up to and including 3.3.66 and have at least one user with the Contributor role or higher.

    An attacker with a Contributor account can store a script in a shortcode attribute. The plugin sanitizes the post content on save, but not the shortcode attribute values. When the page is loaded, the script executes in the browser of other visitors, including administrators. The attacker needs an account, but not a highly privileged one.

    Update to version 3.3.67. The source does not mention another workaround.

    Affected
    Download Manager
    Fixed in
    3.3.67
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.24 %
    percentile 15.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Advanced Woo Labels

    CVE-2026-15662

    Affects you if you run Advanced Woo Labels up to and including version 2.48 and have users with the Contributor role or higher.

    An attacker with a Contributor account can store malicious code in the database via the bg_color parameter. The code runs in the browser of every visitor who opens the affected page. On its own this is annoying but not critical, because the attacker already needs an account.

    The vulnerability is not on the KEV catalog of actively exploited vulnerabilities. That matches the low EPSS of 0.2 percent. I rate it for awareness, because a Contributor account is the hurdle and no active mass exploitation is known.

    Update to version 2.49.

    Affected
    Advanced Woo Labels – Product Labels & Badges for WooCommerce
    Fixed in
    2.49
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.24 %
    percentile 14.5
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    AI Engine – The Chatbot, AI Framework & MCP for WordPress

    CVE-2026-15988

    Affects you if you run the AI Engine plugin in versions up to and including 3.6.5.

    An attacker can trick an administrator of your site into clicking a crafted link. If they do, a new administrator account with attacker-supplied credentials is created without their knowledge. The vulnerability exists because a security check, the nonce, is missing from a specific function. On its own, this is a classic Cross-Site Request Forgery. Combined with how WordPress processes REST requests, it becomes full privilege escalation.

    The attack requires an action by the administrator. That makes it less likely than a vulnerability requiring no interaction, but not harmless. A targeted link in a seemingly legitimate email is enough.

    Update the plugin to version 3.6.6. Then check your user list for unknown administrator accounts.

    Affected
    AI Engine – The Chatbot, AI Framework & MCP for WordPress
    Fixed in
    3.6.6
    CVSS
    8.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.3
    Type
    CWE-352
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Fluent Forms

    CVE-2026-17571

    Affects you if you run Fluent Forms up to and including 6.2.8.

    An attacker can place malicious code in the display if they can trick someone into clicking a crafted link. No login is required. The attack is limited to the browser of the person who clicks and runs in the context of your own site. That makes it less sweeping than a vulnerability that works without interaction, but it is not harmless.

    Update to 6.2.9.

    Affected
    Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    Fixed in
    6.2.9
    CVSS
    6.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.5
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    Powerkit

    CVE-2026-15644

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and your WordPress site has users with the Contributor role or higher.

    An attacker with a Contributor account can plant malicious scripts on a page via the 'style' shortcode attribute. When another user visits that page, the script executes in their browser. That is enough to hijack sessions or trick administrators into actions they did not intend.

    The vulnerability is not on the KEV catalog of actively exploited flaws. It requires an account, but the bar is low: Contributor is the role you give a guest author so they can submit a draft.

    Update Powerkit to version 3.1.1.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Powerkit

    CVE-2026-15645

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and people with the Contributor role or higher have access to your site.

    An attacker with an account of at least the Contributor role can place a script via the nav shortcode attribute. The script executes in the browser of every visitor who loads a page containing that shortcode. The damage depends on what the attacker does with the script, but the door is open.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. That is a snapshot, not a guarantee that it is not being exploited somewhere.

    Update Powerkit to version 3.1.1.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Kadence Blocks

    CVE-2026-18062

    Affects you if you run Kadence Blocks up to and including 3.7.8.1 and allow users with contributor-level access or higher to create posts.

    A stored cross-site scripting vulnerability in the Identity Block. An attacker with contributor access can place scripts that execute whenever someone visits the page. The attack requires the urlTransparent attribute to be set on the block. Without that value, the vulnerable code path is never reached.

    The hole is not exploitable from the outside, but contributor accounts are common in editorial teams and multi-user client projects. Kadence Blocks is widely deployed, so I am including it.

    Update Kadence Blocks to 3.7.8.2.

    Affected
    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
    Fixed in
    3.7.8.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    SureForms

    CVE-2026-7623

    Affects you if you run the SureForms plugin in versions up to and including 2.8.1 on your WordPress site and users with the Contributor role or higher exist.

    Stored cross-site scripting via a block attribute. An attacker with a Contributor account can plant scripts that execute whenever someone visits the page. The hurdle is the account, but the Contributor role is often handed to guest authors without the same scrutiny as an administrator.

    Update to version 2.8.2.

    Affected
    SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
    Fixed in
    2.8.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

345 checked and dismissed, with reasons
  • 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
  • CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.