Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
LatePoint
CVE-2026-5391Affects you if you use the LatePoint plugin in a version up to and including 5.3.2 on your WordPress site and have users with the Contributor role or higher.
A stored cross-site scripting vulnerability in the plugin's shortcode. An authenticated user with at least Contributor privileges can inject malicious code into pages that executes in the browsers of other visitors when the page is loaded. The CVSS of 6.4 is medium, but the vulnerability is listed here because it is present on my own installations, and a successful attack on a trusted site carries the potential for significant collateral damage.
Update LatePoint to version 5.4.0. The source does not provide a workaround that resolves the issue without the update.
- Affected
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
- Fixed in
- 5.4.0
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Post Grid Gutenberg Blocks – PostX
CVE-2026-5158Affects you if you run the PostX plugin up to and including version 5.0.13 on your WordPress site and allow users with at least Contributor privileges to write.
A stored cross-site scripting vulnerability in the plugin's comment block. An authenticated user with the Contributor role or higher can plant scripts that execute in the browser of other visitors when the page is loaded. This opens the door to session theft, redirects, or loading malicious code.
The vulnerability is not rated high on its own because it requires an account. In practice, Contributor accounts are easy to obtain on many installations, for example through open registration or compromised accounts. That is why it is listed here and not filtered out.
Update PostX to version 5.0.14.
- Affected
- Post Grid Gutenberg Blocks – PostX
- Fixed in
- 5.0.14
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.2 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
File Manager
CVE-2026-15991Affects you if you use the WordPress plugin File Manager in versions 6.0 through 6.9 and have users with the subscriber role or higher.
An attacker with a read-only account can read and delete arbitrary files on the server using a specific command in the URL. Deleting the WordPress configuration file allows them to reinstall the site and run their own code. The vulnerability exists because the plugin reads the permission check and the command execution from different sources, and those sources do not match.
Update to version 6.9.1. The source does not provide a workaround.
- Affected
- File Manager
- Fixed in
- 6.9.1
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.61 %
percentile 45.8 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
FluentSMTP
CVE-2026-16636Affects you if you run the FluentSMTP plugin in a version up to and including 2.2.95 and have email logging enabled. An attacker needs no account for this.
An attacker can store malicious code in the email logs by manipulating the recipient display name. The code fires when someone with administrator privileges opens the detail view of a logged email and uses the prev/next navigation. Nothing happens in the list view. The attack requires your WordPress installation to receive and log an email with a manipulated recipient name. The plugin is widespread because it simplifies sending email through many providers.
Update FluentSMTP to version 2.3.0. The source does not name a workaround that avoids the update.
- Affected
- FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP
- Fixed in
- 2.3.0
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.31 %
percentile 23.0 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Forminator Forms
CVE-2026-18325Affects you if you run Forminator Forms up to and including version 1.56.1 and use forms with select fields.
An attacker can store a script in your database without logging in. It runs in the browser of anyone who visits the affected page. The flaw is in overly permissive filtering of field names that start with “select-” and an internal flag the plugin accepts without checking.
Update to version 1.56.2. The source does not name a workaround.
- Affected
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder
- Fixed in
- 1.56.2
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.28 %
percentile 20.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
TranslatePress
CVE-2026-18510Affects you if you run TranslatePress up to and including 3.2.6 and allow comments on your site.
An unauthenticated stored XSS in a translation plugin. An attacker can place malicious scripts in comments without an account, which execute in the browser of other visitors when the page is loaded. TranslatePress is widely used, and multilingual sites often have comments enabled. Moderation of first-time comments delays the attack but does not prevent it, because the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unchanged.
Update to version 3.3.
- Affected
- TranslatePress – Translate Multilingual sites with AI Translation
- Fixed in
- 3.3
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 15.5 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
LightSync Pro
CVE-2026-6147Affects you if you use the WordPress plugin LightSync Pro in a version up to and including 2.1.6 and your installation has users with the Author role or higher.
The function for replacing media files does not validate the file type. An authenticated user with Author privileges can upload an arbitrary file to the server. This opens the path to code execution.
Update the plugin to a version that closes the vulnerability. The source does not name a specific version number for the fix and provides no workaround. Until the update, review the privileges of Authors and other roles and restrict them to the bare minimum.
- Affected
- LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock
- Fixed in
- 2.1.7
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.66 %
percentile 48.1 - Type
- CWE-434
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Multi Uploader for Gravity Forms
CVE-2026-5581Affects you if you use the plugin Multi Uploader for Gravity Forms in a version up to and including 1.1.8 and a form with a multi-upload field is publicly reachable.
A missing capability check in the plugin's delete function. An attacker without an account can permanently delete any media file from your WordPress library if they know the attachment ID. The nonce required for this action is exposed in the source code of any public page containing an upload form. In the worst case, the entire media library can be destroyed.
Update to a version after 1.1.8. If none is available yet, disable the plugin until a fix is released.
- Affected
- Multi Uploader for Gravity Forms
- Fixed in
- 1.1.9
- CVSS
- 9.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.46 %
percentile 37.5 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Material Dashboard
CVE-2026-6079Affects you if you use the Material Dashboard WordPress plugin in a version up to and including 1.4.10.
The plugin lacks a capability check. An attacker without an account can view, execute, and delete scheduled tasks. Viewing may expose personally identifiable information; executing and deleting interferes with your operations.
Update to version 1.4.11.
- Affected
- Material Dashboard
- Fixed in
- 1.4.11
- CVSS
- 7.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.39 %
percentile 32.3 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
VikAppointments Services Booking Calendar
CVE-2026-15918Affects you if you run the VikAppointments Services Booking Calendar plugin in a version up to and including 1.2.19 on your WordPress site.
A parameter that controls how the public reviews list is sorted is taken from the request without validation and placed directly into a database query. An attacker with no account can inject arbitrary SQL through it and read from the database, including sensitive data such as WordPress user credentials.
Update the plugin to version 1.2.20. The source does not name a workaround.
- Affected
- VikAppointments Services Booking Calendar
- Fixed in
- 1.2.20
- CVSS
- 7.5
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.39 %
percentile 31.7 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.