Threat Log

793advisories read
600affect you
193checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. Act now Wordfence

    Easy Form Builder by WhiteStudio – Drag & Drop Form Builder

    CVE-2026-85122

    Affects you if you run Easy Form Builder 4.0.0 through 4.1.3. The flaw can be exploited by an attacker without authentication.

    The plugin does not validate a submitted value against the stored configuration for some form types. Unauthenticated users can therefore store arbitrary content that is rendered unescaped on an administrative page. Web scripts in that content execute whenever someone accesses the injected page.

    I classify this as stored cross-site scripting. It is not listed in the CISA KEV catalog as an actively exploited vulnerability.

    Update to 4.2.0.

    Affected
    Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
    Fixed in
    4.2.0
    CVSS
    8.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.51 %
    percentile 40.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    Master Blocks

    CVE-2026-88824

    Affects you if you run Master Blocks in versions 1.4.1 through 1.4.1.4. Unauthenticated attackers can inject stored scripts.

    One REST route does not check authorization adequately. Unauthenticated attackers can therefore change settings and inject stored cross-site scripting.

    I rate this as serious because the source says the script runs in an administrator's session when that administrator visits an affected admin page.

    Update Master Blocks to 1.5.0.

    Affected
    Master Blocks – Ultimate Blocks for Marketers
    Fixed in
    1.5.0
    CVSS
    8.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.51 %
    percentile 40.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    iGMS Direct Booking

    CVE-2026-88825

    Affects you if you use iGMS Direct Booking through 1.0. Unauthenticated attackers can store arbitrary web scripts in pages.

    I classify this as stored Cross-Site Scripting. The source names insufficient input sanitization and output escaping as the cause.

    The source says the stored scripts execute when an administrator views the plugin settings or a visitor opens a page displaying the booking widget. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 2.0. The source does not name a workaround.

    Affected
    iGMS Direct Booking
    Fixed in
    2.0
    CVSS
    8.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.51 %
    percentile 40.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    All-in-One WP Migration and Backup

    CVE-2026-89064

    Affects you if you run All-in-One WP Migration and Backup through 7.110. The source names no additional condition.

    The plugin provides insufficient protection for credentials. I rate this as relevant because an unauthenticated attacker can cause WordPress Application Passwords or HTTP Basic credentials that are submitted to be stored in the database. The data is stored only as reversibly encoded base64.

    The source also says that the stored credential can be overwritten with a value chosen by the attacker. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 7.111.

    Affected
    All-in-One WP Migration and Backup
    Fixed in
    7.111
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.50 %
    percentile 40.1
    Type
    CWE-522
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    VikBooking Hotel Booking Engine & PMS

    CVE-2026-85127

    Affects you if you use VikBooking Hotel Booking Engine & PMS in an affected version. The affected range runs from 1.8.8 through 1.8.14.

    Stored Cross-Site Scripting through SVG files. Unauthenticated attackers can inject arbitrary web scripts into pages that execute whenever someone accesses the SVG file.

    The source names an administrator viewing a conversation as the context. I rate this as requiring immediate attention. It is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update VikBooking to 1.8.15.

    Affected
    VikBooking Hotel Booking Engine & PMS
    Fixed in
    1.8.15
    CVSS
    8.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.7
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    wp shortcut link and advertisement baner

    CVE-2026-87767

    Affects you if you run the WordPress plugin Shortcut Link and Advertisement Baner through 1.2.0, because the flaw works without login.

    A SQL injection caused by insufficiently checked input in an existing SQL query. The source says unauthenticated attackers can append SQL queries and extract sensitive data from the database.

    I rate this flaw as relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    wp shortcut link and advertisement baner
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Price Drop Alert for Woo Commerce

    CVE-2026-87770

    Affects you if you use Price Drop Alert for Woo Commerce in a version through 1.1. The source describes SQL injection without authentication.

    The source describes insufficiently sanitized input in an SQL query. Unauthenticated attackers can perform SQL injection attacks and extract sensitive data from the database.

    I consider this finding relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    Price Drop Alert for Woo Commerce
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Product Question and Answer

    CVE-2026-87771

    Affects you if you use Product Question and Answer through 1.1.0. Unauthenticated attackers can perform SQL injection against it.

    The plugin does not sufficiently sanitize and escape a user supplied parameter before using it in SQL queries. Unauthenticated attackers can append additional SQL queries and extract sensitive information from the database.

    The source does not name a fixed version or a workaround.

    Affected
    Product Question and Answer
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Tz Weekly Radio Schedule

    CVE-2026-87774

    Affects you if you use Tz Weekly Radio Schedule through 1.8.1. The source describes SQL injection accessible without authentication.

    The source describes SQL injection in a WordPress plugin. A user supplied parameter is insufficiently escaped and used in an SQL query. Unauthenticated attackers can append additional SQL queries and extract sensitive information from the database.

    I rate this as an issue to review immediately. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    Tz Weekly Radio Schedule
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Hide My WP Ghost Security & Firewall

    CVE-2026-86796

    Affects you if you run Hide My WP Ghost Security & Firewall through 7.0.10.

    I classify this as a protection mechanism bypass. The source says unauthenticated attackers can bypass firewall rules and threat detection.

    According to the source, the concealed login and admin URLs can become visible again. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 7.0.11.

    Affected
    Hide My WP Ghost – Security & Firewall
    Fixed in
    7.0.11
    CVSS
    5.3
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    0.34 %
    percentile 25.4
    Type
    CWE-693
    Actively exploited
    not on the KEV list
    Published
    2026-09-16

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

193 checked and dismissed, with reasons
  • 113 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.