Threat Log

691advisories read
600affect you
91checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. This week Wordfence

    Motors – Car Dealership & Classified Listings Plugin

    CVE-2026-91016

    Affects you if you use the Motors WordPress plugin through 1.4.120. Unauthenticated attackers can perform an unauthorized action.

    The source describes an Insecure Direct Object Reference caused by missing validation of a user-controlled key. This lets attackers without a login perform an unauthorized action.

    The source does not say what that action is. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update the plugin to 1.4.121.

    Affected
    Motors – Car Dealership & Classified Listings Plugin
    Fixed in
    1.4.121
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.32 %
    percentile 22.8
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    Choose User Role at Registration for WooCommerce

    CVE-2026-85128

    Affects you if you use Choose User Role at Registration for WooCommerce through 1.3.2 with role selection and public account registration enabled.

    The plugin does not sufficiently validate the role requested during registration against the roles the administrator chose to offer. Unauthenticated attackers can therefore request any role, including administrator, and receive it once the request is approved.

    The source describes privilege escalation caused by insufficient restrictions on the capabilities a user may grant themselves. I consider this relevant even though it is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 1.3.3.

    Affected
    Choose User Role at Registration for WooCommerce
    Fixed in
    1.3.3
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.32 %
    percentile 22.7
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. This week Wordfence

    Paid Membership Subscriptions

    CVE-2026-90922

    Affects you if you use Paid Member Subscriptions through 3.0.8 and the plugin processes membership payments on your WordPress site.

    The plugin does not verify on the server that the amount and currency reported by the payment provider match the pending payment. As a result, unauthenticated attackers can bypass the payment and obtain a paid membership by paying an arbitrarily lower amount.

    I consider this relevant because the described payment bypass does not require a login.

    Update to 3.0.9; the source does not name a workaround.

    Affected
    Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
    Fixed in
    3.0.9
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 20.8
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. This week Wordfence

    Master Addons for Elementor

    CVE-2026-91015

    Affects you if you use Master Addons for Elementor through 3.1.8. Unauthenticated attackers can perform an unauthorized action.

    The plugin does not check authorization for an AJAX action that deactivates Popup Builder popups. It relies instead on a nonce that is publicly output to every visitor.

    The source says unauthenticated attackers can use this to perform an unauthorized action and permanently disable any popup on the site. I classify this as missing authorization. It is not listed in CISA's KEV catalog.

    Update to 3.1.9.

    Affected
    Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
    Fixed in
    3.1.9
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 20.8
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. This week Wordfence

    WP Directory Kit

    CVE-2026-16588

    Affects you if you run WP Directory Kit in versions up to and including 1.5.4 and an authenticated account has custom-level access or higher.

    A blind SQL injection caused by insufficient escaping and insufficient preparation of an existing SQL query. Authenticated attackers with custom-level access or higher can append additional SQL queries to existing queries and use them to extract sensitive information from the database.

    I consider this relevant even though access requires authentication and a specific privilege level. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.

    Update WP Directory Kit to 1.5.5.

    Affected
    WP Directory Kit
    Fixed in
    1.5.5
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.29 %
    percentile 19.8
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. This week Wordfence

    Ad Inserter – Ad Manager & AdSense Ads

    CVE-2026-11984

    Affects you if you use the WordPress plugin Ad Inserter – Ad Manager & AdSense Ads through 2.8.16; the source names no additional condition.

    A missing authorization check lets unauthenticated attackers view administrator-configured header and footer code blocks that have been disabled from public display.

    I classify this as missing authorization. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.

    Update to 2.8.17.

    Affected
    Ad Inserter – Ad Manager & AdSense Ads
    Fixed in
    2.8.17
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 19.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. This week Wordfence

    Bold Page Builder

    CVE-2026-5920

    Affects you if you run Bold Page Builder through 5.9.6 and an authenticated attacker has Contributor-level access or higher.

    I classify this as stored cross-site scripting. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages. Those scripts execute whenever someone accesses an injected page.

    The source cites a bypassable security filter and insufficient sanitization of content. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 5.9.7; the source does not name a workaround.

    Affected
    Bold Page Builder
    Fixed in
    5.9.7
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.28 %
    percentile 18.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. This week Wordfence

    Realtyna Organic IDX plugin + WPL Real Estate

    CVE-2026-91014

    Affects you if you use Realtyna Organic IDX plugin + WPL Real Estate through 5.4.1 and visitors can be tricked into clicking crafted links.

    A reflected cross-site scripting flaw caused by insufficient input sanitization and output escaping. Unauthenticated attackers can inject web scripts into pages that run in a visitor's browser if the visitor clicks a crafted link.

    The flaw is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 5.4.2.

    Affected
    Realtyna Organic IDX plugin + WPL Real Estate
    Fixed in
    5.4.2
    CVSS
    7.1
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.28 %
    percentile 18.6
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    Autopay

    CVE-2026-90923

    Affects you if you use the Autopay WordPress plugin through 5.0.0; unauthenticated attackers can exploit this missing authorization.

    The plugin does not enforce the signature on one of its payment callbacks. This lets unauthenticated attackers access a function without authorization.

    According to the source, stored payment parameters for other customers' orders can be disclosed and deleted. I rate the vulnerability as relevant. It is not listed in CISA's KEV catalog as actively exploited.

    Update Autopay to 5.0.1.

    Affected
    Autopay
    Fixed in
    5.0.1
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 17.9
    Type
    CWE-863
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week Wordfence

    Event Booking Manager for WooCommerce

    CVE-2026-91008

    Affects you if you use Event Booking Manager for WooCommerce before 5.3.8 with its native, non-WooCommerce checkout.

    The plugin does not check ownership or authorization before rendering booking confirmation details. I classify this as an unauthenticated insecure direct object reference.

    The source says this can expose registered attendees' personal information, including full name, email address, phone number, and custom registration fields. It limits exploitation to sites configured with the plugin's native, non-WooCommerce checkout, which is not the default.

    Update to 5.3.8.

    Affected
    Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
    Fixed in
    5.3.8
    CVSS
    3.7
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.26 %
    percentile 16.2
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

91 checked and dismissed, with reasons
  • 107 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 17 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 15 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 11 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 8 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 6 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • CVE-2022-30789Linux-Kernel, lokale Rechteausweitung in NTFS-3G. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS 0,004 und nicht auf der KEV-Liste.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.
  • CVE-2026-15308CPython, Denial of Service im HTML-Parser. Erfordert, dass ein Dienst unkontrollierte HTML-Daten verarbeitet, das ist auf einem Webserver mit WordPress nicht der Fall.
  • CVE-2026-74734Linux-Kernel, Fehler im Firewire-Treiber beim Entladen nach fehlgeschlagener Initialisierung. Erfordert spezielle Firewire-Hardware und einen bereits laufenden Prozess, aus der Ferne nicht auslösbar.
  • CVE-2026-80758Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2026-80914Die konkrete Linux-Kernel-Lücke betrifft Bluetooth-ISO-Sockets und setzt entsprechende Bluetooth-Hardware und -Funktionalität voraus, die für gewöhnliche Webserver keine typische Angriffsfläche ist.
  • CVE-2026-77860Unbound ist ein eigener DNS-Auflösedienst und gehört nicht zum typischen Webserverbetrieb; die Schwachstellen setzen einen betriebenen Unbound-Dienst mit entsprechender DNS-Konfiguration voraus.
  • CVE-2026-87775Tz Weekly Radio Schedule, identische Produkt-, Versions- und Angriffsdaten liegen bereits unter CVE-2026-87774 vor, daher handelt es sich um eine Doppelung.
  • CVE-2026-92541Import and export users and customers beschreibt dieselbe fehlerhafte Berechtigungsprüfung und denselben Fix wie CVE-2026-92540, daher wäre ein eigener Eintrag eine Doppelung.
  • CVE-2026-16542Die SSRF in der WP-Erweiterung Import and export users and customers erfordert ein bereits privilegiertes Administratorkonto und ist daher keine von außen ohne Anmeldung auslösbare Schwachstelle.
  • CVE-2024-44946Linux-Kernel, Use-after-free im KCM-Socket, erfordert Zugriff auf einen solchen Socket und damit bereits einen lokalen Prozess, statt einen üblichen externen Webangriff zu ermöglichen.
  • CVE-2024-36476Linux-Kernel, NULL-Zeiger-Dereferenz im speziellen RDMA-Treiber, benötigt lokalen Zugriff und die RDMA-Funktion und verursacht dabei nur einen Denial-of-Service.
  • CVE-2023-53733Linux-Kernel, lokaler Denial of Service im Netzwerk-Scheduler. Erfordert bereits ein Konto auf der Maschine, ohne Anmeldung nicht auslösbar.
  • CVE-2025-13034cURL, die konkrete Schwäche erfordert QUIC mit ngtcp2 und GnuTLS sowie ausdrücklich deaktivierte Zertifikatsprüfung, weshalb die notwendige Voraussetzung im üblichen TLS-Betrieb fehlt.
  • CVE-2026-1965cURL, die konkrete Schwäche setzt Negotiate-Authentifizierung mit zwei verschiedenen Zugangsdaten und die Wiederverwendung einer noch offenen Verbindung voraus, eine enge Anwendungskonstellation ohne allgemeine Fernwirkung.
  • CVE-2026-33535ImageMagick, Denial of Service über den speziellen X11-Display-Pfad; ein Absturz ohne Datenabfluss ist für dieses Lagebild keine vorrangige Meldung.
  • CVE-2026-10536cURL, der Use-after-free setzt eine ganz bestimmte Folge von Anwendungsaufrufen mit HTTP/2-Stream-Abhängigkeiten voraus und ist nicht über einen erreichbaren Dienst allein auslösbar.