Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
WordPress Core
Wordfence advisoryAffects you if you run WordPress and have users with at least Contributor privileges whom you do not fully control. That applies to most installations with multiple authors.
A stored XSS vulnerability in the Quick Edit field. An attacker with a Contributor account can place scripts in the display name that execute when an administrator accesses the edit screen. The issue only affects sites with a large number of users, which limits the attack surface.
The CVSS of 4.9 is low because an account is required. I list it anyway, because a single compromised Contributor account is enough, and chaining with other vulnerabilities is common.
Update to 4.7.34, 4.8.29, or 4.9.30. The source provides no workaround.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 4.9
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
WordPress Core
Wordfence advisoryAffects you if you run WordPress up to and including 7.0.2 and allow users with the Contributor role or higher to create posts.
A stored cross-site scripting vulnerability in the emoji settings. An attacker with an account at the Contributor level or above can place scripts in posts that execute when the preview is accessed. The vulnerability has a medium CVSS score of 6.4 and is not listed in the CISA KEV catalog of actively exploited vulnerabilities.
I am including it anyway because it affects the core and chaining with other vulnerabilities is common. The fix is in versions 4.7.34, 4.8.29, and 4.9.30. Those are old branches; the source does not name a newer version with the fix.
Update to one of the named versions, depending on your installed branch. The source does not list a newer version with the fix.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 6.4
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
WordPress Core
Wordfence advisoryAffects you if you run WordPress up to and including 7.0.2 and have users with the Author role or above.
A CSS injection that an authenticated user with at least Author privileges can insert into posts. The vulnerability is due to insufficient sanitization of user-supplied CSS. An attacker can alter the appearance and content of pages rendered for other users. The source does not name any further concrete impact.
Update to 4.7.34, 4.8.29, or 4.9.30. The source does not provide a workaround.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 5.5
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
WordPress Core
Wordfence advisoryAffects you if you run WordPress up to and including 7.0.2.
A server-side request forgery that works without authentication. The destination address validation is insufficient, so reserved and internal address ranges are not fully blocked. An attacker can make the application send requests to arbitrary locations, enumerating and interacting with internal services that are otherwise unreachable.
The vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities. The source does not name a workaround.
Update to 4.7.34, 4.8.29, or 4.9.30.
- Affected
- WordPress
- Fixed in
- 4.7.34, 4.8.29, 4.9.30
- CVSS
- 5.8
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-08
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
AI Copilot – Content Generator
CVE-2026-14526Affects you if you use AI Copilot – Content Generator.
wordfence reports: AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route
The CVSS score is 9.8.
This entry deliberately comes without an assessment: the sources did not allow a verified description, and omitting an advisory of this urgency would be the greater harm. The details are in the linked sources.
Check the linked sources and apply the update as soon as it is available.
- Affected
- AI Copilot – Content Generator
- Fixed in
- 1.5.8
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.61 %
percentile 46.7 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-08-07
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
s2Member
CVE-2026-15047Affects you if you run the s2Member plugin for WordPress in a version up to and including 260804 and your installation has users with the Contributor role or higher.
The plugin does not sufficiently escape several shortcode attributes before writing them into an inline script. An authenticated user with Contributor access can use this to place JavaScript in a page that executes when a visitor opens it. The attacker needs an account, but not administrator privileges.
This vulnerability is not listed in the KEV catalog of actively exploited flaws.
Update s2Member to version 260805.
- Affected
- s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
- Fixed in
- 260805
- CVSS
- 6.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, administrator
- Likely to be exploited
- 0.24 %
percentile 14.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-07
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Vitepos
CVE-2026-14237Affects you if you use the Vitepos WordPress plugin and users with the Outlet Manager role can sign in.
Vitepos does not check authorization for each target account when resetting passwords. The Outlet Manager role therefore has an overly broad password-reset capability by default.
An authenticated user with at least that role can reset the password of any user account, including an administrator's, and take over the account. The source also describes privilege escalation to administrator.
Update Vitepos to 3.6.0.
- Affected
- Vitepos
- Fixed in
- 3.6.0
- CVSS
- 7.2
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, administrator
- Likely to be exploited
- 0.26 %
percentile 17.6 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-08-07
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Login Social
CVE-2026-16261Affects you if you use the WordPress plugin Login Social in any version up to and including 1.0.4.
The plugin does not verify whether the person requesting a password change is authorized to do so. An attacker without an account can reset the password of any user, including an administrator, and take over the account.
The source does not name a fixed version or a workaround. Deactivate and remove the plugin until an update appears.
- Affected
- login-social
- CVSS
- 7.5
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.33 %
percentile 26.4 - Type
- CWE-287
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
TrueBooker – Appointment Booking and Scheduler System
CVE-2026-14365Affects you if you run TrueBooker version 1.2.3 or older.
The plugin does not check whether someone is authorized to reset a password. An attacker can change the password of any user, including the administrator, without logging in. They then sign in with the new password and gain full access to the site.
Update to version 1.2.4. Then check your user list for unknown administrator accounts and force a password reset for all users if you find unusual activity.
- Affected
- TrueBooker – Appointment Booking and Scheduler System
- Fixed in
- 1.2.4
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.31 %
percentile 24.0 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
POUCO Import Users
CVE-2026-16256Affects you if you run the POUCO Import Users plugin up to and including version 1.0.0 in WordPress.
The plugin does not check capabilities or nonces on AJAX actions that create and update user accounts. It trusts a role value supplied by the attacker. A stranger can create an administrator account without logging in and take over the site.
The source does not name a fixed version or a workaround. The plugin must be deactivated until an update appears.
- Affected
- POUCO Import Users
- CVSS
- 9.8
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.30 %
percentile 23.0 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
182 checked and dismissed, with reasons
- 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
- 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
- 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
- CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
- CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.