Threat Log

793advisories read
600affect you
193checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. Act now Wordfence

    MIPL Grouped Checkout Fields for WooCommerce

    CVE-2026-8778

    Affects you if you use the WordPress plugin MIPL Grouped Checkout Fields for WooCommerce through 1.2.2.

    The plugin accepts arbitrary file uploads without adequate file type validation. The source says no login is required and that this may make remote code execution possible.

    I therefore classify this vulnerability as severe. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.

    Update to 1.2.3. The source does not name a workaround.

    Affected
    MIPL Checkout Fields Manager for WooCommerce – Customize, Organize & Group Checkout Fields.
    Fixed in
    1.2.3
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    1.14 %
    percentile 65.2
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now BSI CERT-Bund

    cPanel cPanel/WHM

    CVE-2026-67401

    Affects you if your hosting provider uses cPanel/WHM to manage your web hosting service and you have a mail-enabled account there.

    According to the source, an SQL injection in the EmailTrack component lets a mail-enabled account execute code remotely with root privileges.

    The source names neither a fixed version nor a workaround.

    Affected
    cPanel cPanel/WHM
    CVSS
    9.9
    source support@hackerone.com
    Login required
    yes, user account
    Likely to be exploited
    0.96 %
    percentile 59.4
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · BSI CERT-Bund

  3. Act now Wordfence

    AcyMailing

    CVE-2026-77807

    Affects you if you run AcyMailing through version 11.0.4 and have the “Embed images” option enabled in its configuration.

    I rate this finding as relevant. It is a directory traversal flaw through the “user[name]” parameter. Unauthenticated attackers can use it to read arbitrary files on the server, which may contain sensitive information.

    The source names the enabled “Embed images” option as a requirement. The flaw is not listed in CISA’s KEV catalog as actively exploited.

    Update AcyMailing to 11.0.5.

    Affected
    AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
    Fixed in
    11.0.5
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.93 %
    percentile 58.8
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Frontegg SAML SSO

    CVE-2026-75800

    Affects you if you use the Frontegg SAML SSO WordPress plugin on your site in an affected version through and including 1.0.1.

    The source describes a SAML authentication bypass because the plugin does not verify SAML signatures.

    The flaw is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source names neither a fixed version nor a workaround.

    Affected
    Frontegg SAML SSO
    CVSS
    9.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.62 %
    percentile 47.7
    Type
    CWE-287
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    CryptoPayment Gateway

    CVE-2026-81648

    Affects you if you use CryptoPayment Gateway versions 1.2.1 through 1.2.2 on a WordPress site. No login is required to exploit this.

    Insufficient file path validation lets unauthenticated attackers delete arbitrary files on the server. Deleting the right file can lead to remote code execution.

    The source also names overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source names neither a fixed version nor a workaround.

    Affected
    CryptoPayment Gateway
    CVSS
    10.0
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    0.50 %
    percentile 40.1
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Quentn WP

    CVE-2026-84068

    Affects you if you run Quentn WP in versions 1.2.13 through 1.2.14. Unauthenticated attackers can extract arbitrary data from the database.

    Quentn WP insufficiently escapes a user supplied parameter before using it in an SQL query. I rate this as serious because no login is required.

    The source names extracting arbitrary or sensitive data from the database as a possible impact. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update Quentn WP to 1.2.15.

    Affected
    Quentn WP
    Fixed in
    1.2.15
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.45 %
    percentile 36.0
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Vigilant

    CVE-2026-81754

    Affects you if you run the Vigilant WordPress plugin in any version through 2.10.2.

    The source describes stored cross-site scripting in the Vigilant WordPress plugin. Unauthenticated attackers can inject arbitrary web scripts into pages that execute when a user accesses an injected page. The source names insufficient input sanitization and output escaping as the cause.

    The source says no further interaction from the attacker is required after the malicious payload is stored. I rate this as immediate. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 2.10.3; the source does not name a workaround.

    Affected
    Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
    Fixed in
    2.10.3
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.42 %
    percentile 33.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    WPBot

    CVE-2026-87916

    Affects you if you run WPBot through 8.5.9, because the source describes exposure of stored chat sessions without authentication in those versions.

    A missing capability and nonce check when listing stored chat sessions. The source says unauthenticated attackers can retrieve the name, email address, and phone number of every chat visitor.

    Wordfence describes the issue more broadly as exposure of sensitive user or configuration data. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update WPBot to 8.6.0. The source does not name a workaround.

    Affected
    WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services
    Fixed in
    8.6.0
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.34 %
    percentile 25.2
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Rox Appointment Booking

    CVE-2026-87892

    Affects you if you use Rox Appointment Booking before version 1.2.0 and offer bookings through your WordPress site.

    The plugin does not verify the order total or selected payment method on the server when creating a booking. It uses the amount submitted by the client directly for billing. Unauthenticated attackers can therefore create confirmed bookings at an arbitrary price and bypass configured payment-method restrictions.

    I rate this as relevant because no login is required. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.

    Update Rox Appointment Booking to version 1.2.0.

    Affected
    Rox Appointment Booking – Appointment Booking Scheduling Solution
    Fixed in
    1.2.0
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.34 %
    percentile 24.6
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Unlimited Elements For Elementor

    CVE-2026-18561

    Affects you if you run the WordPress plugin Unlimited Elements For Elementor through version 2.0.16. Attackers do not need to log in.

    The source describes SQL injection in the WordPress plugin. According to the source, unauthenticated attackers can extract sensitive information from the database.

    I rate this as requiring immediate attention. The vulnerability is not listed in CISA's KEV catalog as actively exploited.

    Update to 2.0.17.

    Affected
    Unlimited Elements For Elementor
    Fixed in
    2.0.17
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 23.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-10

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

193 checked and dismissed, with reasons
  • 113 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.