Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
Act now Wordfence
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
CVE-2026-85122Affects you if you run Easy Form Builder 4.0.0 through 4.1.3. The flaw can be exploited by an attacker without authentication.
The plugin does not validate a submitted value against the stored configuration for some form types. Unauthenticated users can therefore store arbitrary content that is rendered unescaped on an administrative page. Web scripts in that content execute whenever someone accesses the injected page.
I classify this as stored cross-site scripting. It is not listed in the CISA KEV catalog as an actively exploited vulnerability.
Update to 4.2.0.
- Affected
- Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
- Fixed in
- 4.2.0
- CVSS
- 8.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.51 %
percentile 40.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Master Blocks
CVE-2026-88824Affects you if you run Master Blocks in versions 1.4.1 through 1.4.1.4. Unauthenticated attackers can inject stored scripts.
One REST route does not check authorization adequately. Unauthenticated attackers can therefore change settings and inject stored cross-site scripting.
I rate this as serious because the source says the script runs in an administrator's session when that administrator visits an affected admin page.
Update Master Blocks to 1.5.0.
- Affected
- Master Blocks – Ultimate Blocks for Marketers
- Fixed in
- 1.5.0
- CVSS
- 8.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.51 %
percentile 40.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
iGMS Direct Booking
CVE-2026-88825Affects you if you use iGMS Direct Booking through 1.0. Unauthenticated attackers can store arbitrary web scripts in pages.
I classify this as stored Cross-Site Scripting. The source names insufficient input sanitization and output escaping as the cause.
The source says the stored scripts execute when an administrator views the plugin settings or a visitor opens a page displaying the booking widget. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 2.0. The source does not name a workaround.
- Affected
- iGMS Direct Booking
- Fixed in
- 2.0
- CVSS
- 8.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.51 %
percentile 40.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
All-in-One WP Migration and Backup
CVE-2026-89064Affects you if you run All-in-One WP Migration and Backup through 7.110. The source names no additional condition.
The plugin provides insufficient protection for credentials. I rate this as relevant because an unauthenticated attacker can cause WordPress Application Passwords or HTTP Basic credentials that are submitted to be stored in the database. The data is stored only as reversibly encoded base64.
The source also says that the stored credential can be overwritten with a value chosen by the attacker. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 7.111.
- Affected
- All-in-One WP Migration and Backup
- Fixed in
- 7.111
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.50 %
percentile 40.1 - Type
- CWE-522
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
VikBooking Hotel Booking Engine & PMS
CVE-2026-85127Affects you if you use VikBooking Hotel Booking Engine & PMS in an affected version. The affected range runs from 1.8.8 through 1.8.14.
Stored Cross-Site Scripting through SVG files. Unauthenticated attackers can inject arbitrary web scripts into pages that execute whenever someone accesses the SVG file.
The source names an administrator viewing a conversation as the context. I rate this as requiring immediate attention. It is not listed in the KEV catalog of actively exploited vulnerabilities.
Update VikBooking to 1.8.15.
- Affected
- VikBooking Hotel Booking Engine & PMS
- Fixed in
- 1.8.15
- CVSS
- 8.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.45 %
percentile 36.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
wp shortcut link and advertisement baner
CVE-2026-87767Affects you if you run the WordPress plugin Shortcut Link and Advertisement Baner through 1.2.0, because the flaw works without login.
A SQL injection caused by insufficiently checked input in an existing SQL query. The source says unauthenticated attackers can append SQL queries and extract sensitive data from the database.
I rate this flaw as relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- wp shortcut link and advertisement baner
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.45 %
percentile 36.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Price Drop Alert for Woo Commerce
CVE-2026-87770Affects you if you use Price Drop Alert for Woo Commerce in a version through 1.1. The source describes SQL injection without authentication.
The source describes insufficiently sanitized input in an SQL query. Unauthenticated attackers can perform SQL injection attacks and extract sensitive data from the database.
I consider this finding relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- Price Drop Alert for Woo Commerce
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.45 %
percentile 36.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Product Question and Answer
CVE-2026-87771Affects you if you use Product Question and Answer through 1.1.0. Unauthenticated attackers can perform SQL injection against it.
The plugin does not sufficiently sanitize and escape a user supplied parameter before using it in SQL queries. Unauthenticated attackers can append additional SQL queries and extract sensitive information from the database.
The source does not name a fixed version or a workaround.
- Affected
- Product Question and Answer
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.45 %
percentile 36.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Tz Weekly Radio Schedule
CVE-2026-87774Affects you if you use Tz Weekly Radio Schedule through 1.8.1. The source describes SQL injection accessible without authentication.
The source describes SQL injection in a WordPress plugin. A user supplied parameter is insufficiently escaped and used in an SQL query. Unauthenticated attackers can append additional SQL queries and extract sensitive information from the database.
I rate this as an issue to review immediately. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- Tz Weekly Radio Schedule
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.45 %
percentile 36.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Hide My WP Ghost Security & Firewall
CVE-2026-86796Affects you if you run Hide My WP Ghost Security & Firewall through 7.0.10.
I classify this as a protection mechanism bypass. The source says unauthenticated attackers can bypass firewall rules and threat detection.
According to the source, the concealed login and admin URLs can become visible again. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 7.0.11.
- Affected
- Hide My WP Ghost – Security & Firewall
- Fixed in
- 7.0.11
- CVSS
- 5.3
source contact@wpscan.com - Login required
- no
- Likely to be exploited
- 0.34 %
percentile 25.4 - Type
- CWE-693
- Actively exploited
- not on the KEV list
- Published
- 2026-09-16
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
193 checked and dismissed, with reasons
- 113 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
- 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
- CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.