Threat Log

745advisories read
431affect you
314checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 431 entries
  1. For the record Wordfence

    WP Maps Pro

    CVE-2026-18465

    Affects you if you run the WP Maps Pro plugin in version 6.1.2 or below.

    An attacker can call a plugin action without logging in, which loads a file from the server. The check for whether the caller is authorized to do so is missing. The user-supplied path is also not sufficiently validated. This allows a stranger to include and execute arbitrary existing PHP files on the server.

    Access controls are bypassed, and sensitive data can be read. If other exploitable files are present on the server, such as uploaded images, this can lead to full code execution.

    Update to version 6.1.3.

    Affected
    WP Maps Pro
    Fixed in
    6.1.3
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 13.9
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    MotoPress Hotel Booking

    CVE-2026-15235

    Affects you if you run MotoPress Hotel Booking in a version below 6.0.4 and allow users with low privileges, such as subscribers, to be created on your installation.

    An AJAX endpoint in the plugin returns a booking's full customer details without first checking whether the requester is authorized to see them. Any authenticated user, even a subscriber, can retrieve your customers' names, email addresses, phone numbers, and physical addresses. A data leak through the back door that requires no active exploitation, just an account.

    The vulnerability is not listed in the CISA KEV catalog of actively exploited vulnerabilities. That does not make it harmless, but there is currently no indication of ongoing attacks.

    Update to version 6.0.4.

    Affected
    MotoPress Hotel Booking
    Fixed in
    6.0.4
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 13.3
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    PiWeb Cancel order / Refund request for WooCommerce

    CVE-2026-18603

    Affects you if you run the plugin PiWeb Cancel order / Refund request for WooCommerce in a version up to and including 1.3.4.33 on your WordPress site.

    The plugin does not check whether someone is authorized to add the contents of a previous order to the cart. An attacker can see what other customers ordered without logging in. If a customer is logged in, their cart can be emptied and filled with someone else's order data via a crafted link.

    This vulnerability is not on the KEV catalog of actively exploited flaws. It is still a data privacy issue because order contents are disclosed.

    Update the plugin to version 1.3.4.34.

    Affected
    PiWeb Cancel order / Refund request for WooCommerce
    Fixed in
    1.3.4.34
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 13.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    MStore API

    CVE-2026-16041

    Affects you if you run the MStore API plugin in versions up to 4.20.0 and have WooCommerce product reviews enabled.

    The REST endpoint for creating product reviews checks neither the sender's authorization nor whether the sender purchased the product. A stranger can submit reviews with a chosen name, email address, and star rating without an account. This works even if you have configured reviews to be accepted only from verified owners.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 4.21.0.

    Affected
    MStore API – Create Native Android & iOS Apps On The Cloud
    Fixed in
    4.21.0
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Templately

    CVE-2026-15359

    Affects you if you run the Templately plugin in a version up to and including 3.7.0.

    An attacker without an account can overwrite the administrator's stored cloud connection with an account under their control. The legitimate connection is severed, and the site's template library can be redirected to attacker-controlled content.

    The vulnerability is not on the KEV catalog of actively exploited flaws and has a low probability of near-term exploitation. I am filing it for awareness because it works without authentication, but it does not allow a direct takeover of the site.

    Update to version 3.7.1.

    Affected
    Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!
    Fixed in
    3.7.1
    CVSS
    6.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.20 %
    percentile 10.5
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Download Monitor

    CVE-2026-16608

    Affects you if you run the Download Monitor WordPress plugin in versions up to and including 5.2.5.

    A missing capability check in an AJAX function of the plugin. An unauthenticated attacker can inject arbitrary entries into a site's download statistics and artificially inflate the numbers. The vulnerability is not on the KEV catalog of actively exploited flaws and has a low probability of being exploited soon.

    Update to version 5.2.6.

    Affected
    Download Monitor
    Fixed in
    5.2.6
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 8.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    JetEngine

    CVE-2026-28082

    Affects you if you run the JetEngine WordPress plugin in a version up to and including 3.8.13.1.

    A stored XSS that can be triggered without authentication. An attacker can inject arbitrary scripts into pages. These scripts execute whenever a user accesses a page injected in this way. The fix is available in version 3.8.13.2.

    Update JetEngine to version 3.8.13.2.

    Affected
    JetEngine
    Fixed in
    3.8.13.2
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Photo Gallery, Sliders, Proofing and Themes

    CVE-2026-28141

    Affects you if you run the NextGEN Gallery plugin in a version up to and including 4.2.3.

    A stored XSS that can be triggered without authentication. An attacker can place scripts that execute in the browser of a visitor or administrator as soon as the affected page is loaded. A fix is available as an update.

    Update to version 4.2.4.

    Affected
    Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
    Fixed in
    4.2.4
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    EmbedPress

    CVE-2026-61961

    Affects you if you run the WordPress plugin EmbedPress in a version up to and including 4.5.6.

    Stored XSS that can be triggered without logging in. An attacker can inject arbitrary scripts into pages that execute whenever someone accesses the page. The plugin is widespread because it covers many embedding formats, from PDFs to YouTube videos.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws.

    Update to version 4.6.0.

    Affected
    EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
    Fixed in
    4.6.0
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    Forminator Forms

    CVE-2026-28143

    Affects you if you run the Forminator Forms plugin in a version up to and including 1.56.0.

    A stored XSS that can be triggered without authentication. An attacker can inject scripts into pages that execute in the visitor's browser when the page is accessed. The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 1.56.1.

    Affected
    Forminator Forms – Contact Form, Payment Form & Custom Form Builder
    Fixed in
    1.56.1
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.18 %
    percentile 7.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

314 checked and dismissed, with reasons
  • 161 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2026-7444CSRF erfordert Benutzerinteraktion, nicht aktiv ausgenutzt und geringe Verbreitung; kein dringender Handlungsbedarf.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.