Threat Log

782advisories read
600affect you
182checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. This week Wordfence

    LatePoint

    CVE-2026-5391

    Affects you if you use the LatePoint plugin in a version up to and including 5.3.2 on your WordPress site and have users with the Contributor role or higher.

    A stored cross-site scripting vulnerability in the plugin's shortcode. An authenticated user with at least Contributor privileges can inject malicious code into pages that executes in the browsers of other visitors when the page is loaded. The CVSS of 6.4 is medium, but a contributor account is quickly created or taken over, and a successful attack on a trusted site has far-reaching consequences.

    Update LatePoint to version 5.4.0. The source does not provide a workaround that resolves the issue without the update.

    Affected
    Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
    Fixed in
    5.4.0
    CVSS
    6.4
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.16 %
    percentile 5.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-05

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. Act now Wordfence

    LightSync Pro

    CVE-2026-6147

    Affects you if you use the WordPress plugin LightSync Pro in a version up to and including 2.1.6 and your installation has users with the Author role or higher.

    The function for replacing media files does not validate the file type. An authenticated user with Author privileges can upload an arbitrary file to the server. This opens the path to code execution.

    Update the plugin to a version that closes the vulnerability. The source does not name a specific version number for the fix and provides no workaround. Until the update, review the privileges of Authors and other roles and restrict them to the bare minimum.

    Affected
    LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock
    Fixed in
    2.1.7
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.66 %
    percentile 48.5
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Multi Uploader for Gravity Forms

    CVE-2026-5581

    Affects you if you use the plugin Multi Uploader for Gravity Forms in a version up to and including 1.1.8 and a form with a multi-upload field is publicly reachable.

    A missing capability check in the plugin's delete function. An attacker without an account can permanently delete any media file from your WordPress library if they know the attachment ID. The nonce required for this action is exposed in the source code of any public page containing an upload form. In the worst case, the entire media library can be destroyed.

    Update to a version after 1.1.8. If none is available yet, disable the plugin until a fix is released.

    Affected
    Multi Uploader for Gravity Forms
    Fixed in
    1.1.9
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.46 %
    percentile 37.8
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Material Dashboard

    CVE-2026-6079

    Affects you if you use the Material Dashboard WordPress plugin in a version up to and including 1.4.10.

    The plugin lacks a capability check. An attacker without an account can view, execute, and delete scheduled tasks. Viewing may expose personally identifiable information; executing and deleting interferes with your operations.

    Update to version 1.4.11.

    Affected
    Material Dashboard
    Fixed in
    1.4.11
    CVSS
    7.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 32.6
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    VikAppointments Services Booking Calendar

    CVE-2026-15918

    Affects you if you run the VikAppointments Services Booking Calendar plugin in a version up to and including 1.2.19 on your WordPress site.

    A parameter that controls how the public reviews list is sorted is taken from the request without validation and placed directly into a database query. An attacker with no account can inject arbitrary SQL through it and read from the database, including sensitive data such as WordPress user credentials.

    Update the plugin to version 1.2.20. The source does not name a workaround.

    Affected
    VikAppointments Services Booking Calendar
    Fixed in
    1.2.20
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.39 %
    percentile 32.0
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Easy Post Submission

    CVE-2026-4431

    Affects you if you run the Easy Post Submission plugin in a version up to and including 2.3.0.

    An AJAX endpoint reachable for unauthenticated visitors does not check whether the caller is authorized. An attacker can use it to modify the title, content, excerpt, categories, and tags of arbitrary posts and set the status to draft. The post is then no longer publicly visible.

    Update to version 2.4.0.

    Affected
    Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
    Fixed in
    2.4.0
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.33 %
    percentile 26.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. This week Wordfence

    Page and Post Restriction

    CVE-2026-12000

    Affects you if you use the Page and Post Restriction plugin to hide pages or posts from logged-out visitors.

    The plugin is meant to hide pages and posts from logged-out visitors. The WordPress REST API bypasses that protection. The plugin's internal guards only read a subset of the configuration and miss the global access settings. A stranger can fetch restricted content through the standard REST endpoints without an account.

    The flaw defeats the only purpose of the plugin. Anyone using it to protect content currently has no protection.

    Update the plugin to the latest version and verify that the restricted content is no longer reachable through the REST API.

    Affected
    Page and Post Restriction
    Fixed in
    1.4.2
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.66 %
    percentile 48.7
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. This week Wordfence

    ShopLentor

    CVE-2026-6020

    Affects you if you run ShopLentor up to and including version 3.3.7 and an attacker has obtained administrator access.

    An administrator can call any PHP function through the REST API. The check that limits which functions are allowed is missing. With those privileges the attacker is already deep inside the system, but this hole makes the final step to full compromise particularly easy.

    Update to version 3.3.8.

    Affected
    ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
    Fixed in
    3.3.8
    CVSS
    7.2
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.54 %
    percentile 42.8
    Type
    CWE-470
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    Askeet — Talk to Your WooCommerce Data

    CVE-2026-5651

    Affects you if you use the Askeet plugin in a version up to and including 3.0 and an attacker has an administrator account.

    A SQL injection via the 'sql_query' parameter in multiple AJAX actions. The askeet_is_safe_query() filter is meant to catch dangerous keywords, but it can be bypassed using MySQL conditional comments. The filter strips regular block comments before checking, but MySQL executes conditional comments as code. An attacker with administrator privileges can append their own queries to existing ones and read from the database.

    The vulnerability requires an administrator account. That severely limits the pool of attackers, which is why the rating stays low. Someone with an administrator account can already do significant damage. The additional database path does not make it harmless, though.

    Update to version 3.1.

    Affected
    Askeet — Talk to Your WooCommerce Data
    Fixed in
    3.1
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.38 %
    percentile 30.9
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week Wordfence

    DTX – Dynamic Text Extension for Contact Form 7

    CVE-2026-5116

    Affects you if you run DTX – Dynamic Text Extension for Contact Form 7 in version 5.0.5 or older and have users with Editor-level access or higher.

    Stored cross-site scripting in the admin interface. An attacker with an Editor account can place scripts inside form shortcodes that execute when an administrator runs the form field scan feature. The damage depends on what the script does, but the attacker acts in the administrator's context.

    The vulnerability requires an account, which is why it is not marked urgent. If you have editors you do not control yourself, you should still act.

    Update to the version that corrects the output escaping. The source does not name the fixed version, so check the update in the WordPress plugin directory.

    Affected
    DTX – Dynamic Text Extension for Contact Form 7
    Fixed in
    5.0.6
    CVSS
    4.4
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.30 %
    percentile 22.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

182 checked and dismissed, with reasons
  • 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
  • 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
  • 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
  • CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
  • CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.