Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
This week Wordfence
Theme My Login
CVE-2026-66681Affects you if you run the Theme My Login plugin in a version up to and including 7.1.14.
An attacker can trick an administrator into clicking a crafted link. This causes an action to be performed in the background that the administrator did not intend. The vulnerability stems from missing or incorrect nonce validation in a function of the plugin.
Without the active involvement of an administrator, the vulnerability cannot be exploited. That makes it less urgent, but not harmless.
Update to version 7.1.15.
- Affected
- Theme My Login
- Fixed in
- 7.1.15
- CVSS
- 4.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.11 %
percentile 1.7 - Type
- CWE-352
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
WPMU DEV Dashboard
CVE-2026-15459Affects you if you run the WPMU DEV Dashboard plugin in a version up to and including 5.0.0 and your site is not yet connected to the WPMU DEV Hub. That is the default state after installation.
An attacker can impersonate the Hub without logging in, because the secret key for verifying the request is empty in its default state. The signature is worthless. Combined with a missing replay check and the publicly reachable endpoint, they can trigger arbitrary Hub actions. The most dangerous of these is installing and activating a plugin from an arbitrary URL. This leads to full code execution on the server.
Update to version 5.0.1. The source does not provide a workaround.
- Affected
- WPMU DEV Dashboard
- Fixed in
- 5.0.1
- CVSS
- 8.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.51 %
percentile 41.4 - Type
- CWE-287
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Type Hub
CVE-2026-66665Affects you if you run the Type Hub WordPress plugin in a version up to and including 2.0.6.
An arbitrary file upload with no login required. The plugin does not validate the file type before accepting the file. An attacker can place a file on the server that may make remote code execution possible.
The source does not name a fixed version or a workaround. Disable the plugin until an update is available.
- Affected
- Type Hub
- CVSS
- 10.0
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.29 %
percentile 21.6 - Type
- CWE-434
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Frontend Admin by DynamiApps
CVE-2026-66662Affects you if you run the Frontend Admin by DynamiApps plugin in a version up to and including 3.29.10 on your WordPress installation.
An attacker can gain administrator privileges without logging in. The source does not name a fixed version or a workaround.
The source does not name a fixed version. Until an update is available, deactivate the plugin and check access to user management.
- Affected
- Frontend Admin by DynamiApps
- CVSS
- 9.8
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.27 %
percentile 19.1 - Type
- CWE-266
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
Library Management System
CVE-2026-18666Affects you if you run the Library Management System WordPress plugin through 3.6.6 and have users with the Subscriber role.
The plugin does not adequately prepare a database query that uses user input. Authenticated users with the Subscriber role can use this to read data from the database, including password hashes.
The flaw is not listed in CISA's KEV catalog of actively exploited vulnerabilities.
Update the plugin to 3.6.7.
- Affected
- Library Management System
- Fixed in
- 3.6.7
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.20 %
percentile 10.0 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
WP Data Access
CVE-2026-66663Affects you if you run the WP Data Access plugin in a version up to and including 5.5.79 on your WordPress installation.
A stored cross-site scripting vulnerability. An unauthenticated attacker can inject scripts that execute whenever a user accesses the affected page. The cause is insufficient input sanitization and output escaping.
Update the plugin to version 5.5.80.
- Affected
- WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
- Fixed in
- 5.5.80
- CVSS
- 7.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 9.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Frontend Admin by DynamiApps
CVE-2026-66470Affects you if you run the Frontend Admin by DynamiApps plugin in a version up to and including 3.29.10 on your WordPress installation and have users with the subscriber role or higher.
A missing capability check on a function in the plugin. An attacker with their own account, even just a subscriber account, can perform an unspecified action they are not authorized for. The source does not name the specific action but describes the vulnerability as unauthorized access.
The attack requires an account. That rules out the random passerby, but not a registered user with low privileges.
The source does not name a fixed version. Deactivate the plugin until an update appears, or remove it if it is not strictly necessary.
- Affected
- Frontend Admin by DynamiApps
- CVSS
- 7.1
source audit@patchstack.com - Login required
- yes, user account
- Likely to be exploited
- 0.31 %
percentile 23.4 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
E2Pdf – Export Pdf Tool for WordPress
CVE-2026-66710Affects you if you run the E2Pdf plugin in a version up to and including 1.32.40.
An attacker can include and execute arbitrary files on your server without logging in. This allows reading sensitive data, bypassing access controls, or, if seemingly safe file types can be uploaded, executing custom code.
Update to version 1.32.43.
- Affected
- E2Pdf – Export Pdf Tool for WordPress
- Fixed in
- 1.32.43
- CVSS
- 8.1
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.30 %
percentile 23.0 - Type
- CWE-98
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
FormGent
CVE-2025-15028Affects you if you run the FormGent plugin in version 1.9.2 or earlier and form submissions are displayed on the site.
Insufficient input validation in a form builder. Anyone who fills out the form can deposit scripts that run in the browser of the next visitor who opens the page. This also applies to administrators.
On WordPress, chaining vulnerabilities is the rule. An injected script can hijack an existing session or prepare further attacks. The vulnerability alone seems harmless, but in combination with others it becomes dangerous.
Update to the latest version of the plugin. If none is available, disable the plugin until a fix is released.
- Affected
- FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
- Fixed in
- 1.10.0
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.19 %
percentile 9.0 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
Post Grid Gutenberg Blocks – PostX
CVE-2026-5158Affects you if you run the PostX plugin up to and including version 5.0.13 on your WordPress site and allow users with at least Contributor privileges to write.
A stored cross-site scripting vulnerability in the plugin's comment block. An authenticated user with the Contributor role or higher can plant scripts that execute in the browser of other visitors when the page is loaded. This opens the door to session theft, redirects, or loading malicious code.
The vulnerability is not rated high on its own because it requires an account. In practice, Contributor accounts are easy to obtain on many installations, for example through open registration or compromised accounts. That is why it is listed here and not filtered out.
Update PostX to version 5.0.14.
- Affected
- Post Grid Gutenberg Blocks – PostX
- Fixed in
- 5.0.14
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.16 %
percentile 5.3 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
182 checked and dismissed, with reasons
- 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
- 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
- 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
- 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
- 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
- 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
- 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
- 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
- CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
- CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
- CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
- CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
- CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
- CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
- CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
- CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
- CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
- CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
- CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.