Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
Website Internal Link Optimiser
CVE-2026-66464Affects you if you run the Website Internal Link Optimiser plugin in any version up to and including 5.2.7.
A missing capability check on a function in the plugin. An attacker with no account can perform an unspecified action. The source gives no details, but the fact that no login is required makes this dangerous.
This vulnerability is not listed in the KEV catalog of actively exploited flaws.
The source names no fixed version and no workaround. Deactivate the plugin until an update is released.
- Affected
- Website Internal Link Optimiser
- CVSS
- 6.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 8.4 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
WP Crowdfunding
CVE-2026-14859Affects you if you run the WP Crowdfunding plugin in a version up to and including 2.2.0 and visitors can register as subscribers on your site.
The plugin does not check for the necessary capability in one of its AJAX actions. An authenticated user with the subscriber role can create a crowdfunding campaign post, even though they should not have that permission.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. The CVSS score is 4.3, and the EPSS likelihood is 0.2 percent.
Update to version 2.2.1.
- Affected
- WP Crowdfunding
- Fixed in
- 2.2.1
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.18 %
percentile 8.1 - Type
- CWE-284
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Anti Spam and list cleaner – AcyChecker
CVE-2026-66689Affects you if you run the AcyChecker plugin for WordPress in version 2.0.0 or below.
A missing capability check in a function of the plugin. An unauthenticated attacker can perform an action that should require a login. The source does not specify which action. This vulnerability is not on the KEV catalog of actively exploited flaws, and no EPSS value is available. A fix is available.
Update to version 2.0.1.
- Affected
- Anti Spam and list cleaner – AcyChecker
- Fixed in
- 2.0.1
- CVSS
- 6.3
source audit@patchstack.com - Login required
- yes, user account
- Likely to be exploited
- 0.18 %
percentile 8.0 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
WP Photo Album Plus
CVE-2026-17013Affects you if you run the WP Photo Album Plus plugin in a version up to and including 9.2.07.1 and display one of its galleries on a page.
A parameter is embedded into a script block without being checked. An attacker can craft a link that executes malicious code in your browser when you click it. No login is required, but someone must click the link. This vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
Update to version 9.2.07.002.
- Affected
- WP Photo Album Plus
- Fixed in
- 9.2.07.002
- CVSS
- 6.1
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.16 %
percentile 5.7 - Type
- CWE-79, CWE-287
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Welcart e-Commerce
CVE-2026-16066Affects you if you run Welcart e-Commerce through version 2.11.33 and have users on the site with the Author role or a higher role.
A stored cross-site scripting flaw in a product field. An authenticated user with the Author role or higher can insert arbitrary web scripts that run in the browser of any visitor who opens the affected product page.
The flaw is not listed in CISA's KEV catalog of vulnerabilities known to be actively exploited.
Update Welcart e-Commerce to version 2.11.34.
- Affected
- Welcart e-Commerce
- Fixed in
- 2.11.34
- CVSS
- 5.4
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Appointment Booking Plugin for WooCommerce
CVE-2026-66687Affects you if you run the plugin in a version up to 1.3.2 and allow customer accounts in your shop.
An attacker with a customer account can store malicious scripts that execute in the browser of anyone visiting the affected page. The source describes this as injecting arbitrary web scripts. On its own this does not reach the server, but it is an effective lever for attacks against your visitors.
The vulnerability is not listed in the CISA KEV catalog of actively exploited flaws. It requires a customer account, which reduces the attack surface. That is why it is listed for awareness, not as a call to action.
Update to version 1.4.0.
- Affected
- Appointment Booking Plugin for WooCommerce | Online Booking Calendar & Service Manager
- Fixed in
- 1.4.0
- CVSS
- 6.5
source audit@patchstack.com - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.0 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
ProSolution WP Client
CVE-2026-19050Affects you if you run the ProSolution WP Client plugin up to and including version 2.0.8 and have users with an account at subscriber level or above.
An AJAX handler in the plugin checks neither the capability nor a nonce before using a user-supplied URL for a server-side HTTP request. An attacker with an account, even at the lowest role, can thus make the site issue arbitrary requests to internal services and cloud metadata endpoints. They can choose the method, headers, and body of the request.
This vulnerability is not listed in the KEV catalog of actively exploited flaws.
Update to version 2.0.9.
- Affected
- ProSolution WP Client
- Fixed in
- 2.0.9
- CVSS
- 6.4
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.13 %
percentile 3.1 - Type
- CWE-918
- Actively exploited
- not on the KEV list
- Published
- 2026-08-10
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
WordPress Core
CVE-2026-64638Affects you if you run WordPress. With this flaw that means every installation, regardless of version or configuration.
Reflected XSS on the login screen, with no account needed. An attacker lures a victim to a third-party site that generates a crafted link to the WordPress login. If the victim clicks, malicious code runs in their browser, in the login context. On its own this is a medium finding, because it requires a click and social engineering.
The real edge is in the chain. The dataset describes that this can be escalated to remote code execution, depending on conditions the attacker does not fully control. That is not a theoretical construct, but the reason a core flaw with this damage potential stands here and is not filtered out.
Update to 7.0.3 or the latest patch level of your branch. The fix has been backported all the way to 4.7.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 8.9
source support@hackerone.com - Login required
- no
- Likely to be exploited
- 0.89 %
percentile 56.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
WordPress Core
Wordfence advisoryAffects you if you run WordPress and use internal notes in comments. Comment feeds are reachable out of the box.
Internal notes on comments are meant for editors and administrators. They do not appear on the page, but they end up in the comment feed if you know the address. An attacker needs no account to fetch them. What is in there varies from installation to installation, but it is never meant for the public.
The hole is closed in versions 4.7.34, 4.8.29, and 4.9.30. The source does not name a workaround.
Update to the version that matches your branch. If no update is available, turn off comment feeds until you can switch.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 5.3
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Ray Enterprise Translation
CVE-2026-14548Affects you if you run the Ray Enterprise Translation WordPress plugin in versions up to and including 1.7.3 and have authenticated users with subscriber-level access or above.
A missing capability check in an AJAX action. An authenticated attacker, even with a subscriber account, can overwrite the administrator-configured translation API token with their own value. The source does not name a fixed version and does not name a workaround.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.
The source does not name a fixed version and does not name a workaround. Until an update is available, deactivate the plugin.
- Affected
- Ray Enterprise Translation
- CVSS
- 6.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.17 %
percentile 7.2 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
182 checked and dismissed, with reasons
- 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
- 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
- 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
- CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
- CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.