Threat Log

745advisories read
431affect you
314checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 431 entries
  1. For the record Wordfence

    Kirki

    CVE-2026-15601

    Affects you if you run the Kirki plugin in a version up to and including 6.0.13 and a user with Editor privileges or higher exists.

    A path traversal via crafted ZIP files. An attacker with an account at Editor level or above can twist paths when extracting archives so that files end up outside the intended directory. This allows writing an arbitrary file on the server, which in the next step enables code execution.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. The CVSS of 4.9 reflects the hurdle that an attacker already needs an account with write access.

    Update Kirki to version 6.1.0.

    Affected
    Kirki – Freeform Page Builder, Website Builder & Customizer
    Fixed in
    6.1.0
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.77 %
    percentile 52.4
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Kali Forms

    CVE-2026-16144

    Affects you if you run the Kali Forms plugin in any version up to and including 2.4.20 and at least one form contains a field named thisPermalink, entryCounter, or submission_link. You can check that in the form editor.

    An attacker can execute their own code on your server without logging in. All it takes is submitting a form that contains one of the reserved fields. The plugin's own safeguard only checks whether the placeholders have changed, not whether they come from the outside. A trusted call is fed with attacker data.

    The vulnerability is not on the KEV list and the EPSS likelihood sits at 0.7 percent. That argues against widespread exploitation. Still, act now: if you run a form with the named fields, you have an open door on your system.

    Update to version 2.4.21. The source names no workaround that avoids the update.

    Affected
    Kali Forms — Contact Form & Drag-and-Drop Builder
    Fixed in
    2.4.21
    CVSS
    8.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.69 %
    percentile 49.6
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Single Sign On For TNG

    CVE-2026-15964

    Affects you if you run the WordPress plugin Single Sign On For TNG in any version up to and including 2.0.0.

    A plugin that lets people skip the login. A stranger can reset the password of any user without credentials and then sign in as that user, administrator included. The function that does this is reachable without authentication and does not check whether the request comes from the legitimate account owner.

    Update to the next available version that closes this hole. If none exists yet, disable the plugin until the update ships.

    Affected
    Single Sign On For TNG
    Fixed in
    2.1.0
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.49 %
    percentile 39.8
    Type
    CWE-620
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Subscriptions for WooCommerce

    CVE-2026-15414

    Affects you if you run Subscriptions for WooCommerce up to and including version 2.0.0 and users with the Contributor role or higher have backend access.

    A Contributor can promote themselves to Administrator. The plugin saves a user role from the form when editing a membership plan, without checking whether the sender is allowed to assign that role. The only restriction in the form is a grayed-out field that can be overwritten using the browser's developer tools. The server accepts the value and writes it to the database.

    Update to a version that closes this vulnerability. If no update is available, check the user list for administrators you did not create.

    Affected
    Subscriptions for WooCommerce
    Fixed in
    2.0.1
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.34 %
    percentile 26.3
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    PixelYourSite

    CVE-2026-18059

    Affects you if you run PixelYourSite up to 11.2.1 in a WooCommerce shop and the order received page is reachable, whether visitors are logged in or not.

    The plugin writes sensitive order data into the page source of the order received page as soon as it sees an order ID in the URL. It does not check whether the visitor actually owns that order. An attacker can cycle through order IDs and pull product names, quantities, per-item prices, order totals, and transaction IDs.

    No account is required. The hole is exploitable remotely with nothing more than a guessable or enumerated order ID.

    Update to 11.2.2 or 12.6.1. The source provides no workaround that replaces taking the order received page offline.

    Affected
    PixelYourSite Pro – Your smart PIXEL (TAG) Manager, PixelYourSite – Your smart PIXEL (TAG) & API Manager
    Fixed in
    11.2.2, 12.6.1
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 25.9
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    Pronamic Pay

    CVE-2026-16635

    Affects you if you run Pronamic Pay up to and including version 10.1.0 and use Gravity Forms with a user role update field. An attacker needs an account, even just a subscriber account.

    An attacker with a basic account can make themselves an administrator. The function that sets the role does not check which roles are allowed. It takes the value from the form and writes it directly into the user record. An administrator must have set up the Gravity Forms connection beforehand, otherwise the vulnerability leads nowhere.

    The vulnerability is not on the KEV list and the likelihood of exploitation is 0.3 percent. It is still here because it applies to my systems and an attacker gains administrator rights with a single form submission.

    Update to version 10.2.0. The source names no workaround; only the update helps.

    Affected
    Pronamic Pay
    Fixed in
    10.2.0
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.31 %
    percentile 23.4
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    CubeWP Framework

    CVE-2026-6453

    Affects you if you run the WordPress plugin CubeWP Framework up to version 1.1.30 and an attacker has an account with subscriber-level access or higher.

    A SQL injection in the AJAX function cubewp_remove_relation(). The relation_id parameter is interpolated directly into a SQL query without sufficient sanitization. An attacker with an account that has at least subscriber rights can send their own SQL commands to the database.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 1.1.31.

    Affected
    CubeWP Framework
    Fixed in
    1.1.31
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.28 %
    percentile 20.5
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    W3 Total Cache

    CVE-2026-66695

    Affects you if you run W3 Total Cache in a version up to and including 2.10.2. The vulnerability is triggerable without authentication.

    A path traversal that works without logging in. An attacker can access files outside the intended directory, including configuration files with credentials or other sensitive content. W3 Total Cache is widely deployed, so the attack surface is large.

    Update to version 2.10.3. The source does not name a workaround.

    Affected
    W3 Total Cache
    Fixed in
    2.10.3
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 19.4
    Type
    CWE-35
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Icegram Engage

    CVE-2026-16087

    Affects you if you run Icegram Engage in versions up to and including 3.1.42 and have registered users with at least the Contributor role.

    A SQL injection that works in two steps. An attacker with a Contributor account or higher stores a crafted value that initially looks harmless. During a later database query, that value is inserted into a SQL statement without checking and gets executed. This allows the attacker to read the database.

    The vulnerability requires an account, but Contributor is the lowest writing role in WordPress. Many installations hand it out to guests or customers. That makes the hole relevant for those systems.

    Update to the version that Wordfence lists as fixed. The source does not name a specific version number.

    Affected
    Icegram Engage – Popups, Optins, CTAs & Lead Generation
    Fixed in
    3.1.43
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.27 %
    percentile 19.0
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    GSheetConnector

    CVE-2026-16614

    Affects you if you run the GSheetConnector plugin in version 5.2.1 or older and an attacker has access to an administrator account.

    A SQL injection in the administration interface. An attacker with administrator privileges can append their own database commands to existing queries via the 's' parameter, extracting sensitive information from the database. The damage is limited to what an administrator could already see or export.

    The vulnerability exists because wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters. Single quotes and other metacharacters remain in the parameter and become part of the query.

    Update to version 5.2.2.

    Affected
    GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database
    Fixed in
    5.2.2
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.27 %
    percentile 18.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

314 checked and dismissed, with reasons
  • 161 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 16 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 7 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 4 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2026-7444CSRF erfordert Benutzerinteraktion, nicht aktiv ausgenutzt und geringe Verbreitung; kein dringender Handlungsbedarf.
  • CVE-2024-39929Exim wird auf Georges Servern nicht betrieben, und die Schwachstelle betrifft nur Mailserver, die Exim einsetzen.
  • CVE-2022-49732Lokale Kernel-Schwachstelle ohne KEV-Eintrag und mit minimalem EPSS-Wert; auf gehärteten Servern ohne unberechtigte Konten kein Handlungsbedarf.
  • CVE-2025-21894Lokale Kernel-Schwachstelle in einem Netzwerktreiber, die ein lokales Konto voraussetzt und nicht aktiv ausgenutzt wird; kein Handlungsbedarf für die betreuten Systeme.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-45185Exim wird nicht betrieben, daher keine Betroffenheit für die betreuten Systeme.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52912Lokale Kernel-Lücke im netfilter-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges Systeme nicht relevant ist.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-32282Red Hat Satellite ist nicht Teil des betriebenen Stacks und wird von den Kunden nicht eingesetzt.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.