Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. This week Wordfence

    LatePoint

    CVE-2026-5391

    Affects you if you use the LatePoint plugin in a version up to and including 5.3.2 on your WordPress site and have users with the Contributor role or higher.

    A stored cross-site scripting vulnerability in the plugin's shortcode. An authenticated user with at least Contributor privileges can inject malicious code into pages that executes in the browsers of other visitors when the page is loaded. The CVSS of 6.4 is medium, but the vulnerability is listed here because it is present on my own installations, and a successful attack on a trusted site carries the potential for significant collateral damage.

    Update LatePoint to version 5.4.0. The source does not provide a workaround that resolves the issue without the update.

    Affected
    Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
    Fixed in
    5.4.0
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    Post Grid Gutenberg Blocks – PostX

    CVE-2026-5158

    Affects you if you run the PostX plugin up to and including version 5.0.13 on your WordPress site and allow users with at least Contributor privileges to write.

    A stored cross-site scripting vulnerability in the plugin's comment block. An authenticated user with the Contributor role or higher can plant scripts that execute in the browser of other visitors when the page is loaded. This opens the door to session theft, redirects, or loading malicious code.

    The vulnerability is not rated high on its own because it requires an account. In practice, Contributor accounts are easy to obtain on many installations, for example through open registration or compromised accounts. That is why it is listed here and not filtered out.

    Update PostX to version 5.0.14.

    Affected
    Post Grid Gutenberg Blocks – PostX
    Fixed in
    5.0.14
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    File Manager

    CVE-2026-15991

    Affects you if you use the WordPress plugin File Manager in versions 6.0 through 6.9 and have users with the subscriber role or higher.

    An attacker with a read-only account can read and delete arbitrary files on the server using a specific command in the URL. Deleting the WordPress configuration file allows them to reinstall the site and run their own code. The vulnerability exists because the plugin reads the permission check and the command execution from different sources, and those sources do not match.

    Update to version 6.9.1. The source does not provide a workaround.

    Affected
    File Manager
    Fixed in
    6.9.1
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.61 %
    percentile 45.8
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    FluentSMTP

    CVE-2026-16636

    Affects you if you run the FluentSMTP plugin in a version up to and including 2.2.95 and have email logging enabled. An attacker needs no account for this.

    An attacker can store malicious code in the email logs by manipulating the recipient display name. The code fires when someone with administrator privileges opens the detail view of a logged email and uses the prev/next navigation. Nothing happens in the list view. The attack requires your WordPress installation to receive and log an email with a manipulated recipient name. The plugin is widespread because it simplifies sending email through many providers.

    Update FluentSMTP to version 2.3.0. The source does not name a workaround that avoids the update.

    Affected
    FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP
    Fixed in
    2.3.0
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.31 %
    percentile 23.0
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Forminator Forms

    CVE-2026-18325

    Affects you if you run Forminator Forms up to and including version 1.56.1 and use forms with select fields.

    An attacker can store a script in your database without logging in. It runs in the browser of anyone who visits the affected page. The flaw is in overly permissive filtering of field names that start with “select-” and an internal flag the plugin accepts without checking.

    Update to version 1.56.2. The source does not name a workaround.

    Affected
    Forminator Forms – Contact Form, Payment Form & Custom Form Builder
    Fixed in
    1.56.2
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.28 %
    percentile 20.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    TranslatePress

    CVE-2026-18510

    Affects you if you run TranslatePress up to and including 3.2.6 and allow comments on your site.

    An unauthenticated stored XSS in a translation plugin. An attacker can place malicious scripts in comments without an account, which execute in the browser of other visitors when the page is loaded. TranslatePress is widely used, and multilingual sites often have comments enabled. Moderation of first-time comments delays the attack but does not prevent it, because the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unchanged.

    Update to version 3.3.

    Affected
    TranslatePress – Translate Multilingual sites with AI Translation
    Fixed in
    3.3
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 15.5
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    LightSync Pro

    CVE-2026-6147

    Affects you if you use the WordPress plugin LightSync Pro in a version up to and including 2.1.6 and your installation has users with the Author role or higher.

    The function for replacing media files does not validate the file type. An authenticated user with Author privileges can upload an arbitrary file to the server. This opens the path to code execution.

    Update the plugin to a version that closes the vulnerability. The source does not name a specific version number for the fix and provides no workaround. Until the update, review the privileges of Authors and other roles and restrict them to the bare minimum.

    Affected
    LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock
    Fixed in
    2.1.7
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.66 %
    percentile 48.1
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Multi Uploader for Gravity Forms

    CVE-2026-5581

    Affects you if you use the plugin Multi Uploader for Gravity Forms in a version up to and including 1.1.8 and a form with a multi-upload field is publicly reachable.

    A missing capability check in the plugin's delete function. An attacker without an account can permanently delete any media file from your WordPress library if they know the attachment ID. The nonce required for this action is exposed in the source code of any public page containing an upload form. In the worst case, the entire media library can be destroyed.

    Update to a version after 1.1.8. If none is available yet, disable the plugin until a fix is released.

    Affected
    Multi Uploader for Gravity Forms
    Fixed in
    1.1.9
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.46 %
    percentile 37.5
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Material Dashboard

    CVE-2026-6079

    Affects you if you use the Material Dashboard WordPress plugin in a version up to and including 1.4.10.

    The plugin lacks a capability check. An attacker without an account can view, execute, and delete scheduled tasks. Viewing may expose personally identifiable information; executing and deleting interferes with your operations.

    Update to version 1.4.11.

    Affected
    Material Dashboard
    Fixed in
    1.4.11
    CVSS
    7.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 32.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    VikAppointments Services Booking Calendar

    CVE-2026-15918

    Affects you if you run the VikAppointments Services Booking Calendar plugin in a version up to and including 1.2.19 on your WordPress site.

    A parameter that controls how the public reviews list is sorted is taken from the request without validation and placed directly into a database query. An attacker with no account can inject arbitrary SQL through it and read from the database, including sensitive data such as WordPress user credentials.

    Update the plugin to version 1.2.20. The source does not name a workaround.

    Affected
    VikAppointments Services Booking Calendar
    Fixed in
    1.2.20
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 31.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.