Threat Log

782advisories read
600affect you
182checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. This week Wordfence

    Theme My Login

    CVE-2026-66681

    Affects you if you run the Theme My Login plugin in a version up to and including 7.1.14.

    An attacker can trick an administrator into clicking a crafted link. This causes an action to be performed in the background that the administrator did not intend. The vulnerability stems from missing or incorrect nonce validation in a function of the plugin.

    Without the active involvement of an administrator, the vulnerability cannot be exploited. That makes it less urgent, but not harmless.

    Update to version 7.1.15.

    Affected
    Theme My Login
    Fixed in
    7.1.15
    CVSS
    4.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.11 %
    percentile 1.7
    Type
    CWE-352
    Actively exploited
    not on the KEV list
    Published
    2026-08-06

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    WPMU DEV Dashboard

    CVE-2026-15459

    Affects you if you run the WPMU DEV Dashboard plugin in a version up to and including 5.0.0 and your site is not yet connected to the WPMU DEV Hub. That is the default state after installation.

    An attacker can impersonate the Hub without logging in, because the secret key for verifying the request is empty in its default state. The signature is worthless. Combined with a missing replay check and the publicly reachable endpoint, they can trigger arbitrary Hub actions. The most dangerous of these is installing and activating a plugin from an arbitrary URL. This leads to full code execution on the server.

    Update to version 5.0.1. The source does not provide a workaround.

    Affected
    WPMU DEV Dashboard
    Fixed in
    5.0.1
    CVSS
    8.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.51 %
    percentile 41.4
    Type
    CWE-287
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Type Hub

    CVE-2026-66665

    Affects you if you run the Type Hub WordPress plugin in a version up to and including 2.0.6.

    An arbitrary file upload with no login required. The plugin does not validate the file type before accepting the file. An attacker can place a file on the server that may make remote code execution possible.

    The source does not name a fixed version or a workaround. Disable the plugin until an update is available.

    Affected
    Type Hub
    CVSS
    10.0
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.6
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Frontend Admin by DynamiApps

    CVE-2026-66662

    Affects you if you run the Frontend Admin by DynamiApps plugin in a version up to and including 3.29.10 on your WordPress installation.

    An attacker can gain administrator privileges without logging in. The source does not name a fixed version or a workaround.

    The source does not name a fixed version. Until an update is available, deactivate the plugin and check access to user management.

    Affected
    Frontend Admin by DynamiApps
    CVSS
    9.8
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 19.1
    Type
    CWE-266
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    Library Management System

    CVE-2026-18666

    Affects you if you run the Library Management System WordPress plugin through 3.6.6 and have users with the Subscriber role.

    The plugin does not adequately prepare a database query that uses user input. Authenticated users with the Subscriber role can use this to read data from the database, including password hashes.

    The flaw is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update the plugin to 3.6.7.

    Affected
    Library Management System
    Fixed in
    3.6.7
    CVSS
    4.3
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.20 %
    percentile 10.0
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    WP Data Access

    CVE-2026-66663

    Affects you if you run the WP Data Access plugin in a version up to and including 5.5.79 on your WordPress installation.

    A stored cross-site scripting vulnerability. An unauthenticated attacker can inject scripts that execute whenever a user accesses the affected page. The cause is insufficient input sanitization and output escaping.

    Update the plugin to version 5.5.80.

    Affected
    WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
    Fixed in
    5.5.80
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 9.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. This week Wordfence

    Frontend Admin by DynamiApps

    CVE-2026-66470

    Affects you if you run the Frontend Admin by DynamiApps plugin in a version up to and including 3.29.10 on your WordPress installation and have users with the subscriber role or higher.

    A missing capability check on a function in the plugin. An attacker with their own account, even just a subscriber account, can perform an unspecified action they are not authorized for. The source does not name the specific action but describes the vulnerability as unauthorized access.

    The attack requires an account. That rules out the random passerby, but not a registered user with low privileges.

    The source does not name a fixed version. Deactivate the plugin until an update appears, or remove it if it is not strictly necessary.

    Affected
    Frontend Admin by DynamiApps
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    yes, user account
    Likely to be exploited
    0.31 %
    percentile 23.4
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. This week Wordfence

    E2Pdf – Export Pdf Tool for WordPress

    CVE-2026-66710

    Affects you if you run the E2Pdf plugin in a version up to and including 1.32.40.

    An attacker can include and execute arbitrary files on your server without logging in. This allows reading sensitive data, bypassing access controls, or, if seemingly safe file types can be uploaded, executing custom code.

    Update to version 1.32.43.

    Affected
    E2Pdf – Export Pdf Tool for WordPress
    Fixed in
    1.32.43
    CVSS
    8.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 23.0
    Type
    CWE-98
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    FormGent

    CVE-2025-15028

    Affects you if you run the FormGent plugin in version 1.9.2 or earlier and form submissions are displayed on the site.

    Insufficient input validation in a form builder. Anyone who fills out the form can deposit scripts that run in the browser of the next visitor who opens the page. This also applies to administrators.

    On WordPress, chaining vulnerabilities is the rule. An injected script can hijack an existing session or prepare further attacks. The vulnerability alone seems harmless, but in combination with others it becomes dangerous.

    Update to the latest version of the plugin. If none is available, disable the plugin until a fix is released.

    Affected
    FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
    Fixed in
    1.10.0
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.19 %
    percentile 9.0
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week Wordfence

    Post Grid Gutenberg Blocks – PostX

    CVE-2026-5158

    Affects you if you run the PostX plugin up to and including version 5.0.13 on your WordPress site and allow users with at least Contributor privileges to write.

    A stored cross-site scripting vulnerability in the plugin's comment block. An authenticated user with the Contributor role or higher can plant scripts that execute in the browser of other visitors when the page is loaded. This opens the door to session theft, redirects, or loading malicious code.

    The vulnerability is not rated high on its own because it requires an account. In practice, Contributor accounts are easy to obtain on many installations, for example through open registration or compromised accounts. That is why it is listed here and not filtered out.

    Update PostX to version 5.0.14.

    Affected
    Post Grid Gutenberg Blocks – PostX
    Fixed in
    5.0.14
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

182 checked and dismissed, with reasons
  • 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
  • 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
  • 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
  • CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
  • CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.