Threat Log

626advisories read
281affect you
345checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 281 entries
  1. For the record Wordfence

    Powerkit – Supercharge your WordPress Site

    CVE-2026-15649

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and have users with the Contributor role or higher whom you do not trust completely.

    A Contributor can place stored JavaScript on a page via shortcode attributes. As soon as someone visits that page, the script runs in the visitor's browser. The attacker needs an account, but only the low-level Contributor role. No active exploitation in the wild is currently known, but the vulnerability is publicly documented.

    Update Powerkit to version 3.1.1. The source does not name a workaround that prevents the injection without the update.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    GamiPress

    CVE-2026-16091

    Affects you if you run GamiPress up to and including version 7.9.9.1 and have users with at least a contributor account.

    A stored cross-site scripting vulnerability in the gamipress_rank shortcode. An authenticated attacker with contributor-level access or higher can store scripts that execute in the browser of anyone visiting the affected page.

    On its own the vulnerability is medium severity because an account is required. On many WordPress installations the contributor hurdle is low, however, and combined with another vulnerability that provides an account, medium turns critical fast. That is why it is listed here.

    Update GamiPress to version 7.9.9.2. The source does not name another fix.

    Affected
    GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
    Fixed in
    7.9.9.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Cozy Blocks

    CVE-2026-15950

    Affects you if you run Cozy Blocks in a version up to and including 2.2.11 and have users with the Contributor role or higher.

    An authenticated user with Contributor rights can store malicious scripts in a block attribute. The input is insufficiently sanitized and the output is not escaped, so the script executes in the browser of other visitors. The attacker needs an account, but only the low-level Contributor role. No active exploit is currently known, and the likelihood of exploitation is low.

    Update Cozy Blocks to version 2.2.12.

    Affected
    Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
    Fixed in
    2.2.12
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    GamiPress

    CVE-2026-16090

    Affects you if you run GamiPress up to and including version 7.9.9.1 and users with the Contributor role or higher have access to your site.

    A stored cross-site scripting vulnerability in the gamipress_achievement shortcode. An authenticated user with at least Contributor privileges can place scripts that execute whenever someone accesses the tampered page. WordPress's built-in filtering does not catch this because the value sits inside a shortcode attribute rather than as a raw HTML tag.

    Update to the next available version after 7.9.9.1. If no update has been released yet, deactivate the plugin until the vendor provides a fix.

    Affected
    GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
    Fixed in
    7.9.9.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Easy Property Listings

    CVE-2026-16684

    Affects you if you run Easy Property Listings up to and including version 3.5.24 and hand out accounts with subscriber-level access or higher, including to strangers.

    An attacker with their own account, even just a subscriber, can place a script in the Facebook contact method field. The plugin does not sanitize that input enough. When someone visits a page that displays this field, the script runs in the visitor's browser. What the attacker does with that depends on their script, but the door is open.

    Update to version 3.5.25. The source does not name a workaround that secures the field while the update is not applied.

    Affected
    Easy Property Listings
    Fixed in
    3.5.25
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Kadence Blocks

    CVE-2026-18435

    Affects you if you run Kadence Blocks up to and including 3.7.8 and your WordPress site has users with the Contributor role or higher.

    A Contributor can place a malicious script in the 'toggleIcon' attribute when editing a block. The script executes as soon as someone visits the page. The attacker needs an account, but does not need to be an administrator. Because Kadence Blocks is widely deployed, the vulnerability remains relevant for many installations, even though the bar is higher than for an unprotected endpoint.

    Update Kadence Blocks to 3.7.8.1. Also check whether unexpected Contributor accounts have been created among your users.

    Affected
    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
    Fixed in
    3.7.8.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    GiveWP – Donation Plugin and Fundraising Platform

    CVE-2026-66690

    Affects you if you run the GiveWP donation plugin in a version up to and including 4.16.5 on your WordPress site.

    An attacker can place malicious code in donation forms without logging in. The code executes whenever someone accesses the affected page. The plugin is widely used, so the likelihood that this vulnerability is being actively sought out is high.

    Update GiveWP to version 4.16.5.1.

    Affected
    GiveWP – Donation Plugin and Fundraising Platform
    Fixed in
    4.16.5.1
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Rank Math SEO

    CVE-2026-66702

    Affects you if you run Rank Math SEO in versions up to and including 1.0.274.1.

    A stored cross-site scripting vulnerability that can be triggered without authentication. An attacker can deposit scripts that execute whenever someone accesses an affected page. Rank Math SEO is very widely used, which is why this entry is here even though it is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 1.0.275.

    Affected
    Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
    Fixed in
    1.0.275
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Meta for WooCommerce

    CVE-2026-66707

    Affects you if you run Meta for WooCommerce in a version up to and including 3.7.5.

    An attacker can exploit a stored cross-site scripting vulnerability without logging in. The malicious script stays on the server and runs in the browser of every visitor who loads the affected page. This allows session takeover, hijacking of administrator accounts, or using the site for phishing.

    Update to version 3.7.6.

    Affected
    Meta for WooCommerce
    Fixed in
    3.7.6
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    Meta pixel for WordPress

    CVE-2026-66705

    Affects you if you run Meta pixel for WordPress in a version up to and including 5.2.1.

    A stranger can trigger a stored cross-site scripting vulnerability without logging in. The plugin is widely installed, so the likelihood of someone trying is high.

    Update to version 5.2.2.

    Affected
    Meta pixel for WordPress
    Fixed in
    5.2.2
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 4.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

345 checked and dismissed, with reasons
  • 157 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 10 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2025-71315Lokale Kernel-Schwachstelle in einem DRM-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-43503Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
  • CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.