Threat Log

723advisories read
487affect you
236checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 487 entries
  1. For the record Wordfence

    Powerkit

    CVE-2026-15644

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and your WordPress site has users with the Contributor role or higher.

    An attacker with a Contributor account can plant malicious scripts on a page via the 'style' shortcode attribute. When another user visits that page, the script executes in their browser. That is enough to hijack sessions or trick administrators into actions they did not intend.

    The vulnerability is not on the KEV catalog of actively exploited flaws. It requires an account, but the bar is low: Contributor is the role you give a guest author so they can submit a draft.

    Update Powerkit to version 3.1.1.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Powerkit

    CVE-2026-15645

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and people with the Contributor role or higher have access to your site.

    An attacker with an account of at least the Contributor role can place a script via the nav shortcode attribute. The script executes in the browser of every visitor who loads a page containing that shortcode. The damage depends on what the attacker does with the script, but the door is open.

    The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. That is a snapshot, not a guarantee that it is not being exploited somewhere.

    Update Powerkit to version 3.1.1.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Kadence Blocks

    CVE-2026-18062

    Affects you if you run Kadence Blocks up to and including 3.7.8.1 and allow users with contributor-level access or higher to create posts.

    A stored cross-site scripting vulnerability in the Identity Block. An attacker with contributor access can place scripts that execute whenever someone visits the page. The attack requires the urlTransparent attribute to be set on the block. Without that value, the vulnerable code path is never reached.

    The hole is not exploitable from the outside, but contributor accounts are common in editorial teams and multi-user client projects. Kadence Blocks is widely deployed, so I am including it.

    Update Kadence Blocks to 3.7.8.2.

    Affected
    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
    Fixed in
    3.7.8.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    SureForms

    CVE-2026-7623

    Affects you if you run the SureForms plugin in versions up to and including 2.8.1 on your WordPress site and users with the Contributor role or higher exist.

    Stored cross-site scripting via a block attribute. An attacker with a Contributor account can plant scripts that execute whenever someone visits the page. The hurdle is the account, but the Contributor role is often handed to guest authors without the same scrutiny as an administrator.

    Update to version 2.8.2.

    Affected
    SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
    Fixed in
    2.8.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Powerkit – Supercharge your WordPress Site

    CVE-2026-15649

    Affects you if you run the Powerkit plugin in a version up to and including 3.1.0 and have users with the Contributor role or higher whom you do not trust completely.

    A Contributor can place stored JavaScript on a page via shortcode attributes. As soon as someone visits that page, the script runs in the visitor's browser. The attacker needs an account, but only the low-level Contributor role. No active exploitation in the wild is currently known, but the vulnerability is publicly documented.

    Update Powerkit to version 3.1.1. The source does not name a workaround that prevents the injection without the update.

    Affected
    Powerkit – Supercharge your WordPress Site
    Fixed in
    3.1.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    GamiPress

    CVE-2026-16091

    Affects you if you run GamiPress up to and including version 7.9.9.1 and have users with at least a contributor account.

    A stored cross-site scripting vulnerability in the gamipress_rank shortcode. An authenticated attacker with contributor-level access or higher can store scripts that execute in the browser of anyone visiting the affected page.

    On its own the vulnerability is medium severity because an account is required. On many WordPress installations the contributor hurdle is low, however, and combined with another vulnerability that provides an account, medium turns critical fast. That is why it is listed here.

    Update GamiPress to version 7.9.9.2. The source does not name another fix.

    Affected
    GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
    Fixed in
    7.9.9.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    Cozy Blocks

    CVE-2026-15950

    Affects you if you run Cozy Blocks in a version up to and including 2.2.11 and have users with the Contributor role or higher.

    An authenticated user with Contributor rights can store malicious scripts in a block attribute. The input is insufficiently sanitized and the output is not escaped, so the script executes in the browser of other visitors. The attacker needs an account, but only the low-level Contributor role. No active exploit is currently known, and the likelihood of exploitation is low.

    Update Cozy Blocks to version 2.2.12.

    Affected
    Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
    Fixed in
    2.2.12
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    GamiPress

    CVE-2026-16090

    Affects you if you run GamiPress up to and including version 7.9.9.1 and users with the Contributor role or higher have access to your site.

    A stored cross-site scripting vulnerability in the gamipress_achievement shortcode. An authenticated user with at least Contributor privileges can place scripts that execute whenever someone accesses the tampered page. WordPress's built-in filtering does not catch this because the value sits inside a shortcode attribute rather than as a raw HTML tag.

    Update to the next available version after 7.9.9.1. If no update has been released yet, deactivate the plugin until the vendor provides a fix.

    Affected
    GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
    Fixed in
    7.9.9.2
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    Easy Property Listings

    CVE-2026-16684

    Affects you if you run Easy Property Listings up to and including version 3.5.24 and hand out accounts with subscriber-level access or higher, including to strangers.

    An attacker with their own account, even just a subscriber, can place a script in the Facebook contact method field. The plugin does not sanitize that input enough. When someone visits a page that displays this field, the script runs in the visitor's browser. What the attacker does with that depends on their script, but the door is open.

    Update to version 3.5.25. The source does not name a workaround that secures the field while the update is not applied.

    Affected
    Easy Property Listings
    Fixed in
    3.5.25
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    Kadence Blocks

    CVE-2026-18435

    Affects you if you run Kadence Blocks up to and including 3.7.8 and your WordPress site has users with the Contributor role or higher.

    A Contributor can place a malicious script in the 'toggleIcon' attribute when editing a block. The script executes as soon as someone visits the page. The attacker needs an account, but does not need to be an administrator. Because Kadence Blocks is widely deployed, the vulnerability remains relevant for many installations, even though the bar is higher than for an unprotected endpoint.

    Update Kadence Blocks to 3.7.8.1. Also check whether unexpected Contributor accounts have been created among your users.

    Affected
    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
    Fixed in
    3.7.8.1
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

236 checked and dismissed, with reasons
  • 162 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 6 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 1 advisoryNicht im Bestand.
  • 1 advisoryKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • CVE-2026-1933Samba wird in Georges Stack nicht betrieben und erfordert zudem authentifizierten Zugriff.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2026-7444CSRF erfordert Benutzerinteraktion, nicht aktiv ausgenutzt und geringe Verbreitung; kein dringender Handlungsbedarf.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2024-50047Lokale Kernel-Schwachstelle im CIFS-Treiber ohne KEV und ohne Fernzugriff, betrifft Georges Server nicht unmittelbar.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2024-58239Lokale Kernel-Schwachstelle im TLS-Subsystem ohne KEV und ohne Fernzugriff, keine unmittelbare Gefahr für die Server.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40110Lokale Kernel-Schwachstelle im DRM-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71180Lokale Kernel-Schwachstelle im Counter-Subsystem ohne KEV und ohne Fernzugriff, keine Relevanz für die Server.
  • CVE-2025-71192Lokale Kernel-Schwachstelle im ALSA-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2025-71225Lokaler Bug im md-RAID-Treiber, setzt ein Konto voraus und betrifft Software-RAID, das George nicht einsetzt.
  • CVE-2026-23279Lokale Kernel-Schwachstelle im WLAN-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2026-23396Lokale Kernel-Schwachstelle im WLAN-Treiber ohne KEV und ohne Fernzugriff, keine Relevanz für die Server.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-43476Lokale Kernel-Schwachstelle im IIO-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.