Threat Log

793advisories read
600affect you
193checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. Act now Wordfence

    Robokassa payment gateway for Woocommerce

    CVE-2026-91017

    Affects you if you run the plugin through 1.8.8 with its non-default deferred-payment feature enabled on a WordPress site.

    The plugin does not verify incoming payment notifications on the server. Unauthenticated attackers can therefore forge a notification and mark arbitrary WooCommerce orders as paid or on hold without payment or a valid signature.

    I rate this as requiring immediate action despite its low score. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update the plugin to 1.8.9.

    Affected
    Robokassa payment gateway for Woocommerce
    Fixed in
    1.8.9
    CVSS
    3.7
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    0.14 %
    percentile 2.5
    Type
    CWE-345
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    Admin Menu Editor Pro

    Wordfence advisory

    Affects you if you run Admin Menu Editor Pro versions 2.35 through 2.36 on a WordPress site, because the source identifies this software as backdoored.

    I rate this one as immediate. The plugin contains a backdoor in versions 2.35 through 2.36. Wordfence attributes it to compromised infrastructure.

    The source says unauthenticated attackers can gain backdoored access to sites running the software. It names no other effects.

    The source does not name a fixed version or a workaround.

    Affected
    Admin Menu Editor Pro
    CVSS
    9.8
    source Wordfence
    Actively exploited
    not on the KEV list
    Published
    2026-09-15

    Sources: Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    DS Ad Rotator

    CVE-2026-81402

    Affects you if you use DS Ad Rotator through 0.8. The source says that an attacker does not need to be logged in to upload arbitrary files.

    I classify this finding as severe. DS Ad Rotator does not validate file types or perform the required capability checks during image uploads, allowing arbitrary files, including PHP files, to be uploaded.

    The source says that unauthenticated attackers can perform the upload and that this may make remote code execution possible. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    DS Ad Rotator
    CVSS
    9.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    WP images upload on piclect

    CVE-2026-84171

    Affects you if you run WP images upload on piclect through 1.0. Unauthenticated attackers can upload arbitrary files to the server.

    The source says the plugin does not validate uploaded file names or types before writing them to a publicly accessible directory. Unauthenticated attackers can upload arbitrary files to the affected server.

    The source says this may make remote code execution possible. I classify this as an immediate issue even though it is not listed in the KEV catalog.

    The source names no fixed version and no workaround.

    Affected
    WP images upload on piclect
    CVSS
    9.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    WP Component

    CVE-2026-85681

    Affects you if you use WP Component through 2.2.4. The source describes privilege escalation by unauthenticated attackers.

    I rate this as critical. According to the source, an action available to unauthenticated users lacks capability and nonce checks. Unauthenticated attackers can therefore overwrite any site option and elevate their privileges.

    The source describes a full takeover on a single site installation when registration can be enabled with administrator as the default role. The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    WP Component
    CVSS
    9.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    YouTube Embed, YouTube Gallery, Vimeo Gallery, WordPress plugin

    CVE-2026-88793

    Affects you if you use the YouTube Embed, YouTube Gallery, Vimeo Gallery WordPress plugin in versions 10.0 through 10.3.

    The source describes stored cross-site scripting caused by insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts that execute when a user accesses an injected page.

    According to the source, the scripts can execute in the session of any user viewing the affected content, including an administrator. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin
    CVSS
    8.8
    source contact@wpscan.com
    Login required
    no
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Hoo Companion

    CVE-2026-85129

    Affects you if you run the Hoo Companion WordPress plugin in a version through 1.0.2; the source names no further condition.

    I classify this as stored cross-site scripting. The source describes missing checks and insufficient input sanitization. Unauthenticated attackers can inject web scripts that execute whenever someone accesses an affected page.

    The source also says that the same request destroys the site's existing theme settings. The vulnerability is not listed in CISA's KEV catalog as actively exploited.

    The source does not name a fixed version or a workaround.

    Affected
    Hoo Companion
    CVSS
    8.8
    source contact@wpscan.com
    Login required
    no
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Optimole

    CVE-2026-84829

    Affects you if you use the Optimole WordPress plugin in version 4.2.11 or earlier to serve WordPress pages to visitors from your site.

    I rate this as serious. The source describes stored Cross-Site Scripting caused by insufficient input sanitization and output escaping. No login is required.

    Arbitrary web scripts can be injected into pages and execute whenever a user accesses an affected page. The source does not name any further impact.

    Update to 4.2.12; the source does not name a workaround.

    Affected
    Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
    Fixed in
    4.2.12
    CVSS
    8.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    SAMO Forms

    CVE-2026-80491

    Affects you if you run SAMO Forms through version 1.0.0. The source describes SQL injection in actions that require no authentication.

    I rate this as serious: SAMO Forms does not sufficiently sanitize and escape user input before using it in SQL queries. The source names several unauthenticated actions.

    Unauthenticated attackers can perform SQL injection. Wordfence names extracting sensitive information from the database as a possible consequence. The vulnerability is not listed in CISA's KEV catalog.

    The source does not name a fixed version or a workaround.

    Affected
    SAMO Forms
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Album Cover Finder

    CVE-2026-84047

    Affects you if you run Album Cover Finder through 0.7.0, because unauthenticated users can perform SQL injection attacks against it.

    A SQL injection caused by insufficient sanitization and escaping of a user-supplied parameter before it is used in a SQL query. I rate it as serious because no login is required.

    Unauthenticated attackers can append additional SQL queries to existing queries and extract sensitive information from the database. The vulnerability is not listed in CISA's KEV catalog as actively exploited.

    The source does not name a fixed version or a workaround.

    Affected
    Album Cover Finder
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-14

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

193 checked and dismissed, with reasons
  • 113 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.