Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
Act now Wordfence
IP2Location Country Blocker
CVE-2026-82530Affects you if you use IP2Location Country Blocker through 2.44.0 as a WordPress plugin.
An access control bypass caused by insufficient IP address validation. Unauthenticated remote attackers can bypass IP-based restrictions by setting the X-Real-IP header to an allowlisted IP address. That makes otherwise blocked pages, links, or the entire site accessible.
I rate this as relevant because no login is required. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 2.45.0; the source does not name a workaround.
- Affected
- IP2Location Country Blocker
- Fixed in
- 2.45.0
- CVSS
- 6.9
source disclosure@vulncheck.com - Login required
- no
- Likely to be exploited
- 0.27 %
percentile 18.7 - Type
- CWE-290
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Robokassa payment gateway for Woocommerce
CVE-2026-78536Affects you if you use the Robokassa payment gateway for WooCommerce through version 1.8.9 on a WordPress installation.
I classify this as missing access control. According to the source, a missing capability check on a function allows unauthenticated attackers to perform an unauthorized action.
The source gives no details about that action. The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- Robokassa payment gateway for Woocommerce
- CVSS
- 6.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.25 %
percentile 17.1 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Verified Reviews (Avis Vérifiés)
CVE-2026-81800Affects you if you use the Verified Reviews (Avis Vérifiés) WordPress plugin in a version up to and including 2.4.6 on your WordPress site.
I rate this as critical. The source describes SQL injection caused by insufficient escaping of a user supplied parameter and insufficient preparation of the existing SQL query.
Unauthenticated attackers can append additional SQL queries to existing queries and use them to extract sensitive information from the database. The vulnerability is not listed in CISA's KEV catalog as actively exploited.
The source does not name a fixed version or a workaround.
- Affected
- Verified Reviews (Avis Vérifiés)
- CVSS
- 9.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.25 %
percentile 16.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Sidebar Manager Light
CVE-2026-76562Affects you if you run Sidebar Manager Light through 1.18. The source does not name a fixed version for this vulnerability.
I classify this as stored cross site scripting. Because input is not sufficiently sanitized and output is not properly escaped, unauthenticated attackers can inject arbitrary scripts into pages.
The scripts execute when someone accesses an injected page. The source does not name any further impact.
The source does not name a fixed version or a workaround.
- Affected
- Sidebar Manager Light
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 14.9 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
SiteSkite MCP AI
CVE-2026-81805Affects you if you use the SiteSkite MCP AI WordPress plugin in an affected version up to and including 2.1.5.
The source describes privilege escalation caused by insufficient restrictions on the capabilities a user may grant themselves. An unauthenticated attacker can elevate privileges beyond those intended for the attacker’s role.
I rate this vulnerability as serious. It is not listed in CISA’s KEV catalog as an actively exploited vulnerability.
Update to 2.1.6.
- Affected
- SiteSkite – Secure MCP & AI WebOps. Connect ChatGPT, Claude, or Any AI Agent via MCP
- Fixed in
- 2.1.6
- CVSS
- 8.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.22 %
percentile 12.8 - Type
- CWE-266
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Shirt Product Designer for WooCommerce
CVE-2026-81794Affects you if you run Shirt Product Designer for WooCommerce in a version up to 1.0.4.
I classify this as missing authorization. A function does not check the required capability. As a result, unauthenticated attackers can perform an unauthorized action.
The source does not name a fixed version or a workaround.
- Affected
- Shirt Product Designer for WooCommerce
- CVSS
- 7.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.22 %
percentile 12.4 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
SupportCandy
CVE-2026-81022Affects you if you run the SupportCandy WordPress plugin in versions 3.3.6 through 3.5.2.
The source says the plugin exposes sensitive information when an attacker accesses it without logging in. It names sensitive user or configuration data and the contents of any support ticket.
I consider this relevant because no login is required. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update to 3.5.3.
- Affected
- SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
- Fixed in
- 3.5.3
- CVSS
- 5.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.21 %
percentile 11.0 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Teddy Bear Customize Addon
CVE-2026-14562Affects you if you run the Teddy Bear Customize Addon WordPress plugin through version 1.0.5 and the flaw can be reached without a login.
The source says the plugin checks neither authorization nor ownership before returning WooCommerce order metadata and URLs for uploaded attachments. Unauthenticated attackers can therefore disclose other customers' order and attachment data.
Wordfence also describes the flaw as exposure of sensitive user or configuration data. I classify it as knowledge. It is not listed in CISA's KEV catalog as an actively exploited vulnerability.
The source does not name a fixed version or a workaround.
- Affected
- Teddy Bear Customize Addon
- CVSS
- 5.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.21 %
percentile 11.0 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Post Form, Registration Form, Profile Form for User Profiles,…
CVE-2026-81785Affects you if you use the Post Form WordPress plugin in a version up to and including 2.9.0 on a WordPress site you operate.
The source describes a missing authorization check in a function. This allows unauthenticated attackers to perform an unauthorized action.
I consider this finding relevant. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version or a workaround.
- Affected
- Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
- CVSS
- 6.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.20 %
percentile 9.6 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
المنتور فارسی
CVE-2026-86809Affects you if you run the المنتور فارسی WordPress plugin in versions 2.7.10 through 2.8.1 and use it to process ZarinPal payments.
The plugin does not verify that the payment confirmation returned by the ZarinPal gateway belongs to the transaction being completed. I classify this as a payment bypass.
Unauthenticated attackers can complete a pending order without paying by supplying a valid payment confirmation from a different transaction. This vulnerability is not listed in CISA's KEV catalog as actively exploited.
Update to 2.8.2.
- Affected
- المنتور فارسی
- Fixed in
- 2.8.2
- CVSS
- 5.3
source contact@wpscan.com - Login required
- no
- Likely to be exploited
- 0.11 %
percentile 1.7 - Type
- CWE-345
- Actively exploited
- not on the KEV list
- Published
- 2026-09-09
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
323 checked and dismissed, with reasons
- 112 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 27 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 13 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 12 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 9 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
- 8 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- 4 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
- CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58022Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine, EPSS 0,002 und keine aktive Ausnutzung.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2024-50047Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2018-1000204Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50697Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, EPSS minimal und nicht auf der KEV-Liste.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71200Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71225Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-23279Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-32792Unbound ist ein DNS-Server, der auf Webservern selten betrieben wird, und die Lücke erfordert DNSCrypt-Unterstützung.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.