Threat Log

923advisories read
600affect you
323checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. Act now Wordfence

    IP2Location Country Blocker

    CVE-2026-82530

    Affects you if you use IP2Location Country Blocker through 2.44.0 as a WordPress plugin.

    An access control bypass caused by insufficient IP address validation. Unauthenticated remote attackers can bypass IP-based restrictions by setting the X-Real-IP header to an allowlisted IP address. That makes otherwise blocked pages, links, or the entire site accessible.

    I rate this as relevant because no login is required. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 2.45.0; the source does not name a workaround.

    Affected
    IP2Location Country Blocker
    Fixed in
    2.45.0
    CVSS
    6.9
    source disclosure@vulncheck.com
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 18.7
    Type
    CWE-290
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    Robokassa payment gateway for Woocommerce

    CVE-2026-78536

    Affects you if you use the Robokassa payment gateway for WooCommerce through version 1.8.9 on a WordPress installation.

    I classify this as missing access control. According to the source, a missing capability check on a function allows unauthenticated attackers to perform an unauthorized action.

    The source gives no details about that action. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    Robokassa payment gateway for Woocommerce
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.25 %
    percentile 17.1
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Verified Reviews (Avis Vérifiés)

    CVE-2026-81800

    Affects you if you use the Verified Reviews (Avis Vérifiés) WordPress plugin in a version up to and including 2.4.6 on your WordPress site.

    I rate this as critical. The source describes SQL injection caused by insufficient escaping of a user supplied parameter and insufficient preparation of the existing SQL query.

    Unauthenticated attackers can append additional SQL queries to existing queries and use them to extract sensitive information from the database. The vulnerability is not listed in CISA's KEV catalog as actively exploited.

    The source does not name a fixed version or a workaround.

    Affected
    Verified Reviews (Avis Vérifiés)
    CVSS
    9.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.25 %
    percentile 16.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Sidebar Manager Light

    CVE-2026-76562

    Affects you if you run Sidebar Manager Light through 1.18. The source does not name a fixed version for this vulnerability.

    I classify this as stored cross site scripting. Because input is not sufficiently sanitized and output is not properly escaped, unauthenticated attackers can inject arbitrary scripts into pages.

    The scripts execute when someone accesses an injected page. The source does not name any further impact.

    The source does not name a fixed version or a workaround.

    Affected
    Sidebar Manager Light
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 14.9
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    SiteSkite MCP AI

    CVE-2026-81805

    Affects you if you use the SiteSkite MCP AI WordPress plugin in an affected version up to and including 2.1.5.

    The source describes privilege escalation caused by insufficient restrictions on the capabilities a user may grant themselves. An unauthenticated attacker can elevate privileges beyond those intended for the attacker’s role.

    I rate this vulnerability as serious. It is not listed in CISA’s KEV catalog as an actively exploited vulnerability.

    Update to 2.1.6.

    Affected
    SiteSkite – Secure MCP & AI WebOps. Connect ChatGPT, Claude, or Any AI Agent via MCP
    Fixed in
    2.1.6
    CVSS
    8.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.8
    Type
    CWE-266
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Shirt Product Designer for WooCommerce

    CVE-2026-81794

    Affects you if you run Shirt Product Designer for WooCommerce in a version up to 1.0.4.

    I classify this as missing authorization. A function does not check the required capability. As a result, unauthenticated attackers can perform an unauthorized action.

    The source does not name a fixed version or a workaround.

    Affected
    Shirt Product Designer for WooCommerce
    CVSS
    7.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.4
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    SupportCandy

    CVE-2026-81022

    Affects you if you run the SupportCandy WordPress plugin in versions 3.3.6 through 3.5.2.

    The source says the plugin exposes sensitive information when an attacker accesses it without logging in. It names sensitive user or configuration data and the contents of any support ticket.

    I consider this relevant because no login is required. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 3.5.3.

    Affected
    SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
    Fixed in
    3.5.3
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.0
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Teddy Bear Customize Addon

    CVE-2026-14562

    Affects you if you run the Teddy Bear Customize Addon WordPress plugin through version 1.0.5 and the flaw can be reached without a login.

    The source says the plugin checks neither authorization nor ownership before returning WooCommerce order metadata and URLs for uploaded attachments. Unauthenticated attackers can therefore disclose other customers' order and attachment data.

    Wordfence also describes the flaw as exposure of sensitive user or configuration data. I classify it as knowledge. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.

    The source does not name a fixed version or a workaround.

    Affected
    Teddy Bear Customize Addon
    CVSS
    5.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.0
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    Post Form, Registration Form, Profile Form for User Profiles,…

    CVE-2026-81785

    Affects you if you use the Post Form WordPress plugin in a version up to and including 2.9.0 on a WordPress site you operate.

    The source describes a missing authorization check in a function. This allows unauthenticated attackers to perform an unauthorized action.

    I consider this finding relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    The source does not name a fixed version or a workaround.

    Affected
    Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.20 %
    percentile 9.6
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    المنتور فارسی

    CVE-2026-86809

    Affects you if you run the المنتور فارسی WordPress plugin in versions 2.7.10 through 2.8.1 and use it to process ZarinPal payments.

    The plugin does not verify that the payment confirmation returned by the ZarinPal gateway belongs to the transaction being completed. I classify this as a payment bypass.

    Unauthenticated attackers can complete a pending order without paying by supplying a valid payment confirmation from a different transaction. This vulnerability is not listed in CISA's KEV catalog as actively exploited.

    Update to 2.8.2.

    Affected
    المنتور فارسی
    Fixed in
    2.8.2
    CVSS
    5.3
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    0.11 %
    percentile 1.7
    Type
    CWE-345
    Actively exploited
    not on the KEV list
    Published
    2026-09-09

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

323 checked and dismissed, with reasons
  • 112 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 27 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.