Threat Log

745advisories read
431affect you
314checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 431 entries
  1. For the record Wordfence

    Subscribe2

    CVE-2026-14331

    Affects you if you run the WordPress plugin Subscribe2 in versions up to and including 10.45 and use the public subscription form.

    A visitor can execute malicious code in another visitor's browser via a crafted link. To do so, they have to trick someone into clicking that link. The vulnerability is in the public subscription form; an attacker does not need an account.

    It is not listed in the KEV catalog of actively exploited vulnerabilities. The effort for a successful attack is high because it requires user interaction. That keeps it below the threshold for an urgent alert, but it belongs in the situation report.

    Update Subscribe2 to version 10.46.

    Affected
    Subscribe2 – Form, Email Subscribers & Newsletters
    Fixed in
    10.46
    CVSS
    6.1
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 4.6
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Fluent Forms Pro Add On Pack, Ninja Tables Pro

    Wordfence advisory

    Affects you if you run Fluent Forms Pro version 6.2.7 or Ninja Tables Pro version 5.2.13 in your WordPress installation.

    The vendor's systems were compromised. An attacker embedded a backdoor directly into the plugin code. This allows a stranger to execute arbitrary code on your server without logging in. This is the most severe form of compromise a plugin can suffer.

    Update Fluent Forms Pro to 6.2.8 and Ninja Tables Pro to 5.2.13.

    Affected
    Fluent Forms Pro Add On Pack, Ninja Tables Pro
    Fixed in
    5.2.13, 6.2.8
    CVSS
    9.8
    source Wordfence
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Event Booking Manager for WooCommerce

    CVE-2026-16062

    Affects you if you run the Event Booking Manager for WooCommerce plugin in a version below 5.3.7 and have authenticated users with Contributor-level access or above.

    The plugin allows authenticated users with Contributor-level access and above to inject PHP objects into event content fields. On its own, the plugin contains no usable POP chain to turn this into a direct attack. If another plugin or theme with such a chain is installed, it could lead to file deletion, data retrieval, or code execution.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 5.3.7.

    Affected
    Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
    Fixed in
    5.3.7
    CVSS
    6.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, administrator
    Likely to be exploited
    0.35 %
    percentile 28.2
    Type
    CWE-502
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Element Pack Addons for Elementor

    CVE-2026-14817

    Affects you if you run Element Pack Addons for Elementor in a version below 8.7.13 and have users with the Contributor role or higher.

    A stored cross-site scripting vulnerability. An authenticated user with at least Contributor access can inject JavaScript that executes in the browser of any visitor who views the affected page. The flaw exists because the plugin does not sanitize values from certain data attributes before a bundled front-end library re-parses and renders them in the browser.

    This vulnerability is not listed in the KEV catalog of actively exploited flaws. Still, schedule the update soon, as the plugin is widely used and an attacker can reach many visitors with a single crafted post.

    Update to version 8.7.13.

    Affected
    Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
    Fixed in
    8.7.13
    CVSS
    6.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, administrator
    Likely to be exploited
    0.29 %
    percentile 21.6
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Meta Box

    CVE-2026-15248

    Affects you if you run the Meta Box WordPress plugin in a version below 5.13.1 and have authenticated users with the Contributor role or higher.

    An authenticated user with low privileges can permanently delete other users' media attachments. The check for authorization is missing. This is an insecure direct object reference to items they do not own.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. An attacker needs an account, which raises the bar, but the impact on other users' data is direct.

    Update to version 5.13.1.

    Affected
    Meta Box
    Fixed in
    5.13.1
    CVSS
    5.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, administrator
    Likely to be exploited
    0.28 %
    percentile 20.5
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Product Attachment for WooCommerce

    CVE-2026-16285

    Affects you if you run the Product Attachment for WooCommerce plugin in a version below 2.3.3.

    The plugin does not check whether a requester is authorized when serving media files. An unauthenticated attacker can download any attachment, including private or unlinked files, by guessing its numeric ID.

    Update to version 2.3.3.

    Affected
    Product Attachment for WooCommerce
    Fixed in
    2.3.3
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.26 %
    percentile 18.1
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    Five Star Restaurant Reservations – WordPress Booking Plugin

    CVE-2026-15151

    Affects you if you run the Five Star Restaurant Reservations plugin below version 2.7.23 and users with low-level roles have access to the booking management.

    The plugin lacks a capability check on one of its AJAX actions. An authenticated attacker with a low booking-management role, which by default cannot access the plugin's settings, can reset the configured booking notification rules. This is not full access, but a targeted disruption of operations.

    The vulnerability is not on the KEV catalog of actively exploited flaws, and the likelihood of widespread exploitation is low with an EPSS of 0.2%. I classify it as informational because an attack requires an account and the damage is limited to resetting rules.

    Update to version 2.7.23.

    Affected
    Five Star Restaurant Reservations – WordPress Booking Plugin
    Fixed in
    2.7.23
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 14.4
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    LWS Optimize – All-in-One Speed Booster & Cache Tools

    CVE-2026-16042

    Affects you if you run the LWS Optimize plugin in a version below 3.4 and have authenticated users with the subscriber role or higher.

    The plugin is missing a capability check on a function that flushes the cache. An authenticated user with the subscriber role or higher can trigger this action. The source describes the result as repeated cache rebuilds.

    Update to version 3.4.

    Affected
    LWS Optimize – All-in-One Speed Booster & Cache Tools
    Fixed in
    3.4
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.5
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    FluentBoards

    CVE-2026-14938

    Affects you if you run FluentBoards in a version before 1.95.3 and authenticated users have member access to at least one board.

    An authenticated user with access to one board can read the data of another board through the import function. The check whether the selected board belongs to the user is missing. Titles, descriptions, and file attachments of tasks can be read.

    Update to version 1.95.3.

    Affected
    FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
    Fixed in
    1.95.3
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.9
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    ProfileGrid – User Profiles, Groups and Communities

    CVE-2026-16291

    Affects you if you run ProfileGrid in a version below 5.9.9.8 and have authenticated users with the Subscriber role or higher.

    An authenticated user can delete other users' notifications by guessing the notification identifier. The check whether the notification belongs to the requesting user is missing. The source does not name any further impact.

    Update to version 5.9.9.8.

    Affected
    ProfileGrid – User Profiles, Groups and Communities
    Fixed in
    5.9.9.8
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.15 %
    percentile 4.9
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-08-02

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

314 checked and dismissed, with reasons
  • 161 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2026-7444CSRF erfordert Benutzerinteraktion, nicht aktiv ausgenutzt und geringe Verbreitung; kein dringender Handlungsbedarf.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.