Threat Log

861advisories read
600affect you
261checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. Act now Wordfence

    Return Refund and Exchange For WooCommerce

    CVE-2026-81799

    Affects you if you use the WordPress plugin Return Refund and Exchange For WooCommerce in version 4.6.4 or earlier.

    The plugin does not check the required capability in one function. As a result, an unauthenticated attacker can perform an unauthorized action. I classify this as broken access control.

    The source does not name any further impact. The vulnerability is not listed in CISA's KEV catalog as actively exploited.

    The source does not name a fixed version or a workaround.

    Affected
    Return Refund and Exchange For WooCommerce
    CVSS
    7.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    Simple CAPTCHA with Cloudflare Turnstile

    CVE-2026-66632

    Affects you if you use Simple CAPTCHA with Cloudflare Turnstile up to and including 1.42.1 on pages containing Contact Form 7 forms.

    The source describes unauthenticated arbitrary shortcode execution. Arbitrary shortcode output can therefore be injected into pages containing Contact Form 7 forms. The source gives no further details about the impact.

    It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 1.42.3; the source does not name a workaround.

    Affected
    Simple CAPTCHA with Cloudflare Turnstile
    Fixed in
    1.42.3
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 12.0
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Ultimate Gift Cards for WooCommerce

    CVE-2026-19436

    Affects you if you use the Ultimate Gift Cards for WooCommerce WordPress plugin in a version before 3.2.10.

    The source describes a payment bypass. Unauthenticated attackers can obtain gift card store credit worth more than the amount actually paid.

    I rate this as immediate. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 3.2.10. The source does not name a workaround.

    Affected
    Ultimate Gift Cards for WooCommerce
    Fixed in
    3.2.10
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.3
    Type
    CWE-284
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Salon Booking System

    CVE-2026-81793

    Affects you if you use the Salon Booking System WordPress plugin in versions through and including 10.31.5.

    The plugin fails to check the required capability for a function. As a result, unauthenticated attackers can perform an unauthorized action.

    The source does not name a fixed version or a workaround.

    Affected
    Salon Booking System – Appointment Booking for Salons, Barbershops & Spas
    CVSS
    6.5
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 10.8
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    miniOrange 2FA

    CVE-2026-77771

    Affects you if you use miniOrange 2FA in versions 6.2.8 through 6.3.0. The source describes a bypass of two-factor authentication.

    The source describes a bypass of the second factor that can be used by unauthenticated attackers. I classify this as requiring immediate action.

    The NVD names an attacker who already knows the victim's password as a condition. It also describes unlimited one-time-passcode guesses and a validation endpoint with no attempt limit. The flaw is not listed in CISA's KEV catalog as actively exploited.

    Update to 6.3.1 or 19.3.

    Affected
    miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator)
    Fixed in
    19.3, 6.3.1
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.19 %
    percentile 9.0
    Type
    CWE-287
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    WP Compress – Instant Performance & Speed Optimization

    Wordfence advisory

    Affects you if you run WP Compress through 7.22.01 in a fresh or Lite/Free installation with no api_key already stored.

    A missing authorization check lets unauthenticated attackers link the site to an attacker-controlled WP Compress account and overwrite plugin settings. I rate this as serious because the shared api_key can then be exposed.

    According to the source, that key enables full control over cache purging, file deletion, opcode cache invalidation, and other privileged plugin operations. The source expressly limits the issue to installations where no api_key is already stored.

    Update to 7.22.38.

    Affected
    WP Compress – Instant Performance & Speed Optimization
    Fixed in
    7.22.38
    CVSS
    5.3
    source Wordfence
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Jetpack – WP Security, Backup, Speed, & Growth

    Wordfence advisory

    Affects you if you use Jetpack in versions 16.1 through 16.1.2. The source describes stored cross-site scripting there.

    I classify this as stored cross-site scripting. Unauthenticated attackers can inject arbitrary web scripts into pages. Those scripts execute whenever someone accesses an injected page.

    The vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update Jetpack to 16.1.3.

    Affected
    Jetpack – WP Security, Backup, Speed, & Growth
    Fixed in
    16.1.3
    CVSS
    7.2
    source Wordfence
    Actively exploited
    not on the KEV list
    Published
    2026-09-08

    Sources: Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Loops & Logic

    CVE-2026-16960

    Affects you if you run the Loops & Logic WordPress plugin through 4.2.0. The source names no additional access requirement.

    The plugin does not restrict access to template data to the data a visitor is permitted to see. Unauthenticated users can read arbitrary user records, including email addresses and roles, as well as arbitrary site options.

    I rate this as immediately relevant. The data describes exposure of sensitive user or configuration data.

    Update to 4.3.0.

    Affected
    Loops & Logic
    Fixed in
    4.3.0
    CVSS
    7.5
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.35 %
    percentile 28.7
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-09-07

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    SEO Flow by LupsOnline

    CVE-2026-78362

    Affects you if you run SEO Flow by LupsOnline in versions 3.0.0 through 3.0.2 and the plugin is configured; no login is required.

    The plugin does not correctly validate credentials supplied with its API requests. An unauthenticated attacker can therefore be served as the administrator who configured the plugin and take over the site.

    Wordfence also describes privilege escalation because users can grant themselves more capabilities than their role allows. I rate this as critical. It is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update to 3.0.3.

    Affected
    SEO Flow by LupsOnline
    Fixed in
    3.0.3
    CVSS
    9.8
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.34 %
    percentile 27.7
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-09-07

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    Music Store WordPress eCommerce

    CVE-2026-82304

    Affects you if you use the Music Store WordPress eCommerce plugin before 1.4.5, which processes user input in SQL queries.

    I classify this as an unauthenticated SQL injection. The source says insufficiently processed user input can reach existing SQL queries. That can allow additional queries to be run and sensitive information to be extracted from the database.

    It is not listed in the CISA KEV catalog as an actively exploited vulnerability.

    Update to 1.4.5; the source does not name a workaround.

    Affected
    Music Store – WordPress eCommerce
    Fixed in
    1.4.5
    CVSS
    8.6
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.32 %
    percentile 25.6
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-09-07

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

261 checked and dismissed, with reasons
  • 138 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 31 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 18 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 13 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • 11 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 10 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 8 advisoriesEine eigenständige Serveranwendung wie Keycloak, Zabbix oder Snipe-IT. So etwas installiert niemand aus Versehen: wer sie betreibt, hat sich für sie entschieden und kennt ihren Update-Weg. Auf einem Webserver mit WordPress ist sie nicht enthalten, und ihre Lücken erreichen eine WordPress-Seite nicht.
  • 7 advisoriesJava-Servertechnik wie Tomcat, Jenkins oder Log4j. WordPress ist in PHP geschrieben, auf einem üblichen Webserver läuft gar kein Java, eine Java-Lücke findet dort schlicht nichts vor, worin sie ausgeführt werden könnte. Auch der große Log4j-Fall von 2021 betraf WordPress-Server aus genau diesem Grund nicht.
  • CVE-2025-10263Linux-Kernel, die konkrete Meldung betrifft Arm-Prozessoren und besondere Ausnahmelevel, also eine hardware- und architekturspezifische Variante statt des allgemeinen Serverbetriebs.
  • CVE-2026-1933Samba ist ein Dateifreigabedienst für Windows-Netzwerke, auf einem reinen Webserver mit WordPress läuft er üblicherweise nicht.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2022-49732Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-39964Linux-Kernel, Fehler im Krypto-Subsystem. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.
  • CVE-2026-15308CPython, Denial of Service im HTML-Parser. Erfordert, dass ein Dienst unkontrollierte HTML-Daten verarbeitet, das ist auf einem Webserver mit WordPress nicht der Fall.
  • CVE-2026-13149Red Hat Ansible Automation Platform, eine Automatisierungsplattform, die in der Welt der Leser nicht vorkommt.
  • CVE-2026-92541Import and export users and customers beschreibt dieselbe fehlerhafte Berechtigungsprüfung und denselben Fix wie CVE-2026-92540, daher wäre ein eigener Eintrag eine Doppelung.
  • CVE-2026-89003WPeMatico RSS Feed Fetcher, authentifizierte SSRF, ist in dieser Meldung inhaltlich bereits durch CVE-2026-89000 abgedeckt.
  • CVE-2026-89005WPeMatico RSS Feed Fetcher, authentifiziertes gespeichertes Cross-Site-Scripting, ist in dieser Meldung inhaltlich bereits durch CVE-2026-89002 abgedeckt.
  • CVE-2026-94680The Post Grid, authentifiziertes gespeichertes Cross-Site-Scripting, ist in dieser Meldung inhaltlich bereits durch CVE-2026-94671 abgedeckt.
  • CVE-2026-16542Die SSRF in der WP-Erweiterung Import and export users and customers erfordert ein bereits privilegiertes Administratorkonto und ist daher keine von außen ohne Anmeldung auslösbare Schwachstelle.