Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
Act now Wordfence
OTP Login & Register Woocommerce
CVE-2026-12215Affects you if you use OTP Login & Register Woocommerce through 2.7.2 and an account's phone number is known.
The limit on one-time-code attempts is flawed. An attacker can therefore guess the one-time code for a registered account without signing in.
The source names a full WordPress login as the impact, including administrator accounts. The attacker needs the target account's registered phone number. This issue is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 2.7.3.
- Affected
- OTP Login & Register Woocommerce
- Fixed in
- 2.7.3
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.32 %
percentile 22.4 - Type
- CWE-434
- Actively exploited
- not on the KEV list
- Published
- 2026-09-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Sticky Chat Widget
CVE-2026-15462Affects you if you run the WordPress plugin Sticky Chat Widget in version 1.4.2 or earlier. The flaw can be exploited without a login.
A SQL injection in the WordPress plugin. Unauthenticated attackers can append additional SQL queries to existing queries and use them to extract sensitive information from the database.
I rate this finding as serious. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.
Update the plugin to version 1.4.3.
- Affected
- Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
- Fixed in
- 1.4.3
- CVSS
- 7.5
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.30 %
percentile 20.6 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Booking for Appointments and Events Calendar – Amelia
CVE-2026-77689Affects you if you run Amelia 9.0 through 9.8.0. Unauthenticated booking requests can bypass payment and mark bookings as paid.
The plugin does not verify that a payment was actually collected before recording a booking as paid. It trusts the payment gateway named in a public, unauthenticated booking request, even when the site has never configured that gateway. Unauthenticated attackers can therefore obtain confirmed, fully paid appointments and events without any payment being collected.
I classify this as relevant information. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.
Update to 9.8.1.
- Affected
- Booking for Appointments and Events Calendar – Amelia
- Fixed in
- 9.8.1
- CVSS
- 5.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.30 %
percentile 20.5 - Type
- CWE-284
- Actively exploited
- not on the KEV list
- Published
- 2026-09-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Ultimate Gift Cards for WooCommerce
CVE-2026-19439Affects you if you run Ultimate Gift Cards for WooCommerce in versions 3.0.3 through 3.2.9 and no login is required.
I rate this as a relevant flaw: The plugin does not check authorization when displaying gift card details. Unauthenticated attackers can retrieve gift cards attached to arbitrary orders and disclose customer data, balances, and dates.
The source says versions 3.0.3 through 3.2.8 disclose the same data without the redemption code. In 3.2.9, the plugin can also disclose the live redemption code, which anyone holding it can spend. The source classifies the flaw as sensitive information exposure.
Update to 3.2.10.
- Affected
- Ultimate Gift Cards for WooCommerce
- Fixed in
- 3.2.10
- CVSS
- 7.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.26 %
percentile 15.3 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-09-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Drag and Drop File Upload for Elementor Forms
CVE-2026-18351Affects you if you use the WordPress plugin Drag and Drop File Upload for Elementor Forms through 1.6.0 on a WordPress site.
I rate this as a critical vulnerability. The source describes file uploads without authentication. Insufficient file type validation can allow files that may be executable to be uploaded. That makes remote code execution possible.
The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 1.6.1; the source does not name a workaround.
- Affected
- Drag and Drop File Upload for Elementor Forms
- Fixed in
- 1.6.1
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.77 %
percentile 54.1 - Type
- CWE-434
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Direct Download for WooCommerce
CVE-2026-15019Affects you if you run Direct Download for WooCommerce through 1.19 and have at least 1 free, virtual, downloadable product.
I rate this as a serious vulnerability. It is directory traversal. Unauthenticated attackers can read arbitrary files on the server, which may contain sensitive information.
The product ownership check only confirms that some free, virtual, downloadable product exists. It does not verify that the requested file path belongs to that product's configured downloads. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- Direct Download for WooCommerce
- CVSS
- 7.5
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.68 %
percentile 50.8 - Type
- CWE-22
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Teddy Bear Customize Addon
CVE-2026-14560Affects you if you use Teddy Bear Customize Addon through 1.0.5. Unauthenticated attackers can upload files to the affected site's server.
The WordPress plugin does not properly validate uploaded files. This allows unauthenticated attackers to upload arbitrary PHP files to the affected site's server.
The source says this may make remote code execution possible. I rate this as requiring immediate attention. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.
The source does not name a fixed version or a workaround.
- Affected
- Teddy Bear Customize Addon
- CVSS
- 10.0
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.44 %
percentile 37.9 - Type
- CWE-94
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Advanced Product Fields Extended for WooCommerce
CVE-2026-81789Affects you if you use Advanced Product Fields Extended for WooCommerce through 3.1.6. Unauthenticated attacks are possible.
The source describes insufficient validation of file paths. Unauthenticated attackers can use this to delete arbitrary files on the server. The source names remote code execution as a possible consequence when the right file is deleted, such as wp-config.php.
I rate this as serious. It is not listed in the KEV catalog of actively exploited vulnerabilities. That does not prove it is not being exploited.
The source does not name a fixed version or a workaround.
- Affected
- Advanced Product Fields Extended for WooCommerce
- Fixed in
- 3.1.7
- CVSS
- 8.6
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.36 %
percentile 29.8 - Type
- CWE-22
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Teddy Bear Customize Addon
CVE-2026-14559Affects you if you use the Teddy Bear Customize Addon WordPress plugin through version 1.0.5 and it has registered user accounts.
The plugin does not verify a user's password before authentication. As a result, unauthenticated attackers can log in as any registered user, including administrators, by supplying only that user's email address.
I rate this vulnerability as severe. It is not listed in CISA's KEV catalog as an actively exploited vulnerability. The source names no impact beyond logging in as other users.
The source does not name a fixed version or a workaround.
- Affected
- Teddy Bear Customize Addon
- CVSS
- 9.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.28 %
percentile 20.4 - Type
- CWE-287
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Advanced Customized Prompts
CVE-2026-14563Affects you if you run the Advanced Customized Prompts WordPress plugin through version 1.0.1. The source names no additional requirement.
The plugin does not verify the password before issuing a session for a supplied email address. I classify this as privilege escalation. The source says unauthenticated attackers can log in as other users, including administrators, or create new accounts.
The source does not name a fixed version or a workaround.
- Affected
- Advanced Customized Prompts
- CVSS
- 9.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.28 %
percentile 20.4 - Type
- CWE-287
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
193 checked and dismissed, with reasons
- 113 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 26 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
- 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
- CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.