Threat Log

616advisories read
527affect you
89checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 527 entries
  1. Act now Wordfence

    Material Dashboard

    CVE-2026-6079

    Affects you if you use the Material Dashboard WordPress plugin in a version up to and including 1.4.10.

    The plugin lacks a capability check. An attacker without an account can view, execute, and delete scheduled tasks. Viewing may expose personally identifiable information; executing and deleting interferes with your operations.

    Update to version 1.4.11.

    Affected
    Material Dashboard
    Fixed in
    1.4.11
    CVSS
    7.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 32.6
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    VikAppointments Services Booking Calendar

    CVE-2026-15918

    Affects you if you run the VikAppointments Services Booking Calendar plugin in a version up to and including 1.2.19 on your WordPress site.

    A parameter that controls how the public reviews list is sorted is taken from the request without validation and placed directly into a database query. An attacker with no account can inject arbitrary SQL through it and read from the database, including sensitive data such as WordPress user credentials.

    Update the plugin to version 1.2.20. The source does not name a workaround.

    Affected
    VikAppointments Services Booking Calendar
    Fixed in
    1.2.20
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 32.0
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Easy Post Submission

    CVE-2026-4431

    Affects you if you run the Easy Post Submission plugin in a version up to and including 2.3.0.

    An AJAX endpoint reachable for unauthenticated visitors does not check whether the caller is authorized. An attacker can use it to modify the title, content, excerpt, categories, and tags of arbitrary posts and set the status to draft. The post is then no longer publicly visible.

    Update to version 2.4.0.

    Affected
    Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
    Fixed in
    2.4.0
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 26.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. This week Wordfence

    Page and Post Restriction

    CVE-2026-12000

    Affects you if you use the Page and Post Restriction plugin to hide pages or posts from logged-out visitors.

    The plugin is meant to hide pages and posts from logged-out visitors. The WordPress REST API bypasses that protection. The plugin's internal guards only read a subset of the configuration and miss the global access settings. A stranger can fetch restricted content through the standard REST endpoints without an account.

    The flaw defeats the only purpose of the plugin. Anyone using it to protect content currently has no protection.

    Update the plugin to the latest version and verify that the restricted content is no longer reachable through the REST API.

    Affected
    Page and Post Restriction
    Fixed in
    1.4.2
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.66 %
    percentile 48.7
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. This week Wordfence

    ShopLentor

    CVE-2026-6020

    Affects you if you run ShopLentor up to and including version 3.3.7 and an attacker has obtained administrator access.

    An administrator can call any PHP function through the REST API. The check that limits which functions are allowed is missing. With those privileges the attacker is already deep inside the system, but this hole makes the final step to full compromise particularly easy.

    Update to version 3.3.8.

    Affected
    ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
    Fixed in
    3.3.8
    CVSS
    7.2
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.54 %
    percentile 42.8
    Type
    CWE-470
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. This week Wordfence

    Askeet — Talk to Your WooCommerce Data

    CVE-2026-5651

    Affects you if you use the Askeet plugin in a version up to and including 3.0 and an attacker has an administrator account.

    A SQL injection via the 'sql_query' parameter in multiple AJAX actions. The askeet_is_safe_query() filter is meant to catch dangerous keywords, but it can be bypassed using MySQL conditional comments. The filter strips regular block comments before checking, but MySQL executes conditional comments as code. An attacker with administrator privileges can append their own queries to existing ones and read from the database.

    The vulnerability requires an administrator account. That severely limits the pool of attackers, which is why the rating stays low. Someone with an administrator account can already do significant damage. The additional database path does not make it harmless, though.

    Update to version 3.1.

    Affected
    Askeet — Talk to Your WooCommerce Data
    Fixed in
    3.1
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.38 %
    percentile 30.9
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. This week Wordfence

    DTX – Dynamic Text Extension for Contact Form 7

    CVE-2026-5116

    Affects you if you run DTX – Dynamic Text Extension for Contact Form 7 in version 5.0.5 or older and have users with Editor-level access or higher.

    Stored cross-site scripting in the admin interface. An attacker with an Editor account can place scripts inside form shortcodes that execute when an administrator runs the form field scan feature. The damage depends on what the script does, but the attacker acts in the administrator's context.

    The vulnerability requires an account, which is why it is not marked urgent. If you have editors you do not control yourself, you should still act.

    Update to the version that corrects the output escaping. The source does not name the fixed version, so check the update in the WordPress plugin directory.

    Affected
    DTX – Dynamic Text Extension for Contact Form 7
    Fixed in
    5.0.6
    CVSS
    4.4
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.30 %
    percentile 22.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. This week Wordfence

    PrettyLinks

    CVE-2026-5062

    Affects you if you run PrettyLinks up to and including 3.6.20 and an attacker has gained administrator access.

    An SQL injection in the search function of the Pretty Links listing page. An attacker with administrator privileges can use it to read the database. The vulnerability requires a login with the highest rights, which limits the damage but does not rule it out. Someone who is already an administrator can use this path to access data the WordPress backend does not normally show.

    Update to 3.6.21.

    Affected
    PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links
    Fixed in
    3.6.21
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.27 %
    percentile 18.9
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    Super Progressive Web Apps

    CVE-2026-5108

    Affects you if you run the Super Progressive Web Apps plugin in a version up to and including 2.2.43 and an attacker has gained administrator access.

    An administrator can place scripts in the offline message setting that later execute in the browsers of other visitors. The entry is stored without sanitization and passed to the front end without escaping. That is stored cross-site scripting.

    The vulnerability requires administrator privileges. Someone who has those can already do almost anything. It becomes dangerous when an attacker takes over an administrator account and uses it to permanently embed malicious code in the site, code that fires every time the offline message is triggered.

    Update to version 2.2.44.

    Affected
    Super Progressive Web Apps
    Fixed in
    2.2.44
    CVSS
    4.4
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.24 %
    percentile 16.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week Wordfence

    Total Upkeep

    CVE-2026-66708

    Affects you if you run the Total Upkeep backup plugin by BoldGrid in a version up to and including 1.17.2.

    A missing capability check on a function in the plugin. An attacker with no account can perform an unauthorized action. The source does not specify which action. A backup plugin has access to the entire file system and database, so any unauthorized action here is a serious finding.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. Updating to 1.17.3 closes it.

    Update Total Upkeep to version 1.17.3.

    Affected
    Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
    Fixed in
    1.17.3
    CVSS
    8.2
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.9
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

89 checked and dismissed, with reasons
  • 122 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 18 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 16 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 9 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 7 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
  • 7 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • 6 advisoriesVirtualisierung und Container-Orchestrierung. Bei einem gemieteten Server ist das die Schicht darunter, und die betreibt der Anbieter: als Mieter können Sie dort weder etwas prüfen noch etwas einspielen. Wer eigene Virtualisierungs-Wirte betreibt, weiß das und braucht dafür eine eigene Beobachtung.
  • CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
  • CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
  • CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.