Threat Log

829advisories read
600affect you
229checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. This week BSI CERT-Bund

    Linux Kernel

    CVE-2026-31692

    Affects you if you use the Linux kernel. The source describes a vulnerability that can be used to bypass security safeguards.

    I rate this as a medium-severity vulnerability. According to the source, a local unprivileged user with a user namespace can create network interfaces in arbitrary network namespaces, including init_net.

    The source describes a missing permission check for the peer network namespace. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update the Linux kernel when a fixed version becomes available; the source names neither a fixed version nor a workaround.

    Affected
    Linux Kernel
    CVSS
    5.5
    source nvd@nist.gov
    Login required
    yes, user account
    Likely to be exploited
    0.12 %
    percentile 2.0
    Actively exploited
    not on the KEV list
    Published
    2026-09-22

    Sources: NVD · EPSS · BSI CERT-Bund

  2. Act now Wordfence

    HUSKY Products Filter for WooCommerce Professional

    CVE-2026-92969

    Affects you if you run HUSKY Products Filter for WooCommerce Professional through 1.4.4; the vulnerability is exploitable without authentication.

    According to the source, a Local File Inclusion allows arbitrary PHP files on the server to be included and executed. That allows any PHP code in those files to run. The source names bypassing access controls, obtaining sensitive data, and code execution when PHP files can be uploaded and included as possible effects.

    I classify this as a serious finding. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 1.4.5; the source does not name a workaround.

    Affected
    HUSKY – Products Filter for WooCommerce Professional
    Fixed in
    1.4.5
    CVSS
    8.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    1.10 %
    percentile 64.3
    Type
    CWE-98
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    TranslatePress

    CVE-2026-89412

    Affects you if you run TranslatePress up to and including 3.3.5. The source names no additional condition for being affected by this issue.

    I classify this as stored cross-site scripting. According to the source, unauthenticated attackers can inject arbitrary web scripts into pages. Those scripts execute when someone accesses an affected page.

    The source names insufficient input sanitization and output escaping as the cause. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update TranslatePress to 3.3.6.

    Affected
    TranslatePress – Translate Multilingual sites with AI Translation
    Fixed in
    3.3.6
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.53 %
    percentile 42.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Meta Box

    CVE-2026-13355

    Affects you if you run Meta Box AIO through 3.7.2, Meta Box Frontend Submission through 4.5.6, or Meta Box User Profile through 3.11.0.

    I rate this as critical. According to the source, a missing authorization check lets unauthenticated attackers overwrite the content of any page and insert a shortcode. The source text instead names Meta Box AIO versions through 3.11.0, while the title names 3.7.2.

    The source names privilege escalation to Administrator as the impact. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update the affected extension to one of the fixed versions named by the source, 3.12.0 or 4.6.0; the source does not map those versions to the 3 products.

    Affected
    Meta Box AIO, Meta Box Frontend Submission, Meta Box User Profile
    Fixed in
    3.12.0, 4.6.0
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.44 %
    percentile 35.7
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    Handily

    CVE-2025-14487

    Affects you if you use the Handily WordPress plugin in a version up to and including 1.0.3, because the flaw concerns Stripe payment settings.

    Missing authorization checks allow unauthenticated attackers to modify Stripe payment settings. These include publishable and secret keys, email addresses, success URLs, and cancel URLs.

    The source names redirecting payments to the attackers' own Stripe accounts as a possible consequence. I consider this relevant despite a medium CVSS score. It is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to 1.0.4; the source does not name a workaround.

    Affected
    Handily
    Fixed in
    1.0.4
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 12.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. This week BSI CERT-Bund

    Python

    CVE-2021-3737 and 1 more

    Affects you if you run Python on a server and a script is running that makes HTTP requests to external servers.

    The source bundles several vulnerabilities. One of them lies in Python's HTTP client: a server your script contacts can send back a response that drives the script into an infinite loop, consuming CPU. The source does not detail the other vulnerability, it mentions possible disclosure of information. It does not say which component is affected.

    This vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. I classify it as informational, because exploitation requires a server your script contacts itself, and the effect is limited to availability, as far as the source describes it.

    The source does not name a fixed version or a workaround. As long as no update is available, the only option is to restrict your scripts' HTTP requests to trusted servers.

    Affected
    Python
    CVSS
    7.5
    source nvd@nist.gov
    Login required
    no
    Likely to be exploited
    11.59 %
    percentile 95.9
    Type
    CWE-835, CWE-400
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · BSI CERT-Bund

  7. This week BSI CERT-Bund

    Python, lxml

    CVE-2021-43818

    Affects you if you use lxml and use the HTML Cleaner in security-sensitive contexts for HTML or SVG content.

    The HTML Cleaner lets certain crafted script content pass through, including SVG files embedded through data URIs. The BSI assesses the vulnerability as allowing a remote, anonymous attacker to execute arbitrary code.

    Update lxml to 4.6.5, and note that the source does not name a workaround.

    Affected
    Python
    CVSS
    8.2
    source security-advisories@github.com
    Login required
    no
    Likely to be exploited
    2.48 %
    percentile 83.7
    Type
    CWE-74, CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · BSI CERT-Bund

  8. This week Wordfence

    Product Feed Manager for WooCommerce

    CVE-2026-15095

    Affects you if you use Product Feed Manager for WooCommerce through 6.6.43 and an attacker has Shop Manager-level access or higher.

    The plugin allows path traversal to delete arbitrary files on the server. An attacker needs an authenticated account with Shop Manager-level access or higher.

    I consider this relevant despite the login requirement because the source says deleting critical files can lead to remote code execution. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 6.6.44.

    Affected
    Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels
    Fixed in
    6.6.44
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    1.17 %
    percentile 66.1
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    WP Travel Engine

    CVE-2026-9231

    Affects you if you run WP Travel Engine through 6.8.0 and an authenticated account with Contributor-level access or higher exists.

    The source describes a local file inclusion through the wte_get_template function. Authenticated attackers with contributor-level access or higher can include and execute arbitrary PHP files on the server. The source names bypassing access controls, obtaining sensitive data, and code execution as possible consequences when PHP files can be uploaded and included.

    I rate this as relevant even though it requires authentication. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update WP Travel Engine to 6.8.1.

    Affected
    WP Travel Engine – Tour Booking Plugin – Tour Operator Software
    Fixed in
    6.8.1
    CVSS
    7.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.98 %
    percentile 60.6
    Type
    CWE-98
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week BSI CERT-Bund

    Python

    CVE-2024-12718 and 3 more

    Affects you if you use Python 3.12 or later and the tarfile module to extract untrusted archives with the data or tar filters.

    I classify this as an advisory covering multiple vulnerabilities. The source names the tarfile module as the affected component and says files outside the intended extraction directory can be modified, including file metadata and permissions.

    The source also points to a possible bypass of security safeguards. It does not assign each effect to an individual vulnerability. The issue is not listed in CISA's KEV catalog as actively exploited.

    Update Python; the source does not name a fixed version or a workaround.

    Affected
    Python
    CVSS
    5.3
    source cna@python.org
    Login required
    no
    Likely to be exploited
    0.77 %
    percentile 53.6
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-09-21

    Sources: NVD · EPSS · BSI CERT-Bund

229 checked and dismissed, with reasons
  • 102 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 23 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 18 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 17 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 14 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 6 advisoriesJava-Servertechnik wie Tomcat, Jenkins oder Log4j. WordPress ist in PHP geschrieben, auf einem üblichen Webserver läuft gar kein Java, eine Java-Lücke findet dort schlicht nichts vor, worin sie ausgeführt werden könnte. Auch der große Log4j-Fall von 2021 betraf WordPress-Server aus genau diesem Grund nicht.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-49623Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2023-53109Linux-Kernel, Datenrennen in der IP-Tunnel-Sendeverarbeitung; die Meldung belegt weder eine aus der Ferne ausnutzbare Sicherheitswirkung noch aktive Ausnutzung.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2026-33845GnuTLS, Lücke im DTLS-Handshake, DTLS wird auf typischen Webservern mit WordPress nicht verwendet.
  • CVE-2026-74734Linux-Kernel, Fehler im Firewire-Treiber beim Entladen nach fehlgeschlagener Initialisierung. Erfordert spezielle Firewire-Hardware und einen bereits laufenden Prozess, aus der Ferne nicht auslösbar.
  • CVE-2026-80758Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2026-77860Unbound ist ein eigener DNS-Auflösedienst und gehört nicht zum typischen Webserverbetrieb; die Schwachstellen setzen einen betriebenen Unbound-Dienst mit entsprechender DNS-Konfiguration voraus.
  • CVE-2026-94574GNU wget in Windows-Builds, die Lücke setzt eine für unprivilegierte Windows-Benutzer beschreibbare Konfigurationsdatei voraus und betrifft keinen Linux-Serverdienst.
  • CVE-2026-87775Tz Weekly Radio Schedule, identische Produkt-, Versions- und Angriffsdaten liegen bereits unter CVE-2026-87774 vor, daher handelt es sich um eine Doppelung.
  • CVE-2026-92541Import and export users and customers beschreibt dieselbe fehlerhafte Berechtigungsprüfung und denselben Fix wie CVE-2026-92540, daher wäre ein eigener Eintrag eine Doppelung.
  • CVE-2026-16542Die SSRF in der WP-Erweiterung Import and export users and customers erfordert ein bereits privilegiertes Administratorkonto und ist daher keine von außen ohne Anmeldung auslösbare Schwachstelle.
  • CVE-2026-76559Die SSRF in WP Import Export Lite erfordert eine Import-Berechtigung, die regelmäßig ein bereits privilegiertes Administratorkonto voraussetzt, und ist daher keine von außen ohne Anmeldung auslösbare Schwachstelle.