Threat Log

782advisories read
600affect you
182checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
10 of 600 entries
  1. This week Wordfence

    PrettyLinks

    CVE-2026-5062

    Affects you if you run PrettyLinks up to and including 3.6.20 and an attacker has gained administrator access.

    An SQL injection in the search function of the Pretty Links listing page. An attacker with administrator privileges can use it to read the database. The vulnerability requires a login with the highest rights, which limits the damage but does not rule it out. Someone who is already an administrator can use this path to access data the WordPress backend does not normally show.

    Update to 3.6.21.

    Affected
    PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links
    Fixed in
    3.6.21
    CVSS
    4.9
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.27 %
    percentile 18.9
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    Super Progressive Web Apps

    CVE-2026-5108

    Affects you if you run the Super Progressive Web Apps plugin in a version up to and including 2.2.43 and an attacker has gained administrator access.

    An administrator can place scripts in the offline message setting that later execute in the browsers of other visitors. The entry is stored without sanitization and passed to the front end without escaping. That is stored cross-site scripting.

    The vulnerability requires administrator privileges. Someone who has those can already do almost anything. It becomes dangerous when an attacker takes over an administrator account and uses it to permanently embed malicious code in the site, code that fires every time the offline message is triggered.

    Update to version 2.2.44.

    Affected
    Super Progressive Web Apps
    Fixed in
    2.2.44
    CVSS
    4.4
    source security@wordfence.com
    Login required
    yes, administrator
    Likely to be exploited
    0.24 %
    percentile 16.1
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. This week Wordfence

    Total Upkeep

    CVE-2026-66708

    Affects you if you run the Total Upkeep backup plugin by BoldGrid in a version up to and including 1.17.2.

    A missing capability check on a function in the plugin. An attacker with no account can perform an unauthorized action. The source does not specify which action. A backup plugin has access to the entire file system and database, so any unauthorized action here is a serious finding.

    The vulnerability is not listed in the KEV catalog of actively exploited flaws. Updating to 1.17.3 closes it.

    Update Total Upkeep to version 1.17.3.

    Affected
    Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
    Fixed in
    1.17.3
    CVSS
    8.2
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.22 %
    percentile 12.9
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    Remote API

    CVE-2026-14602

    Affects you if you run the Remote API WordPress plugin in version 0.2 or older.

    The plugin accepts data from the outside and processes it without checking authentication first. An attacker can inject a PHP object. On its own, the plugin has no known chain to cause harm. But if another plugin or theme provides such a chain, the attacker can delete files, retrieve sensitive data, or execute code.

    This vulnerability is not listed in the KEV catalog of actively exploited vulnerabilities.

    Remove or deactivate the plugin until a fixed version appears. The source does not name a patched release.

    Affected
    Remote API
    CVSS
    9.0
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.52 %
    percentile 42.0
    Type
    CWE-94
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    WP Directory Kit

    CVE-2026-16589

    Affects you if you use the WordPress plugin Directory Kit in version 1.5.4 or earlier and have users with Subscriber-level access.

    An AJAX action in the plugin does not sufficiently handle a parameter before it reaches a database query. It also lacks authorization and request checks.

    An authenticated user with Subscriber-level access or higher can manipulate database queries and retrieve sensitive information from the database.

    Update Directory Kit to version 1.5.5.

    Affected
    WP Directory Kit
    Fixed in
    1.5.5
    CVSS
    7.7
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.21 %
    percentile 12.2
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    Nexter Blocks

    CVE-2025-15678

    Affects you if you use Nexter Blocks through 5.0.1 and authors can upload SVG files to your WordPress website.

    Nexter Blocks does not adequately sanitize uploaded SVG files. Authenticated users with author-level access or higher can use this to store web scripts in pages.

    The script runs when someone accesses an affected page. This flaw is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update Nexter Blocks to 5.0.2.

    Affected
    Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
    Fixed in
    5.0.2
    CVSS
    6.1
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 4.6
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    BNE Testimonials

    CVE-2026-15245

    Affects you if you use BNE Testimonials through 2.0.8.1 and users with the Contributor role or higher can edit content.

    An authenticated user with the Contributor role or higher can inject JavaScript into content. The code runs in the browser of every visitor who opens the manipulated page.

    This vulnerability is not listed in CISA's KEV catalog of actively exploited vulnerabilities.

    Update BNE Testimonials to 2.0.8.2.

    Affected
    BNE Testimonials
    Fixed in
    2.0.8.2
    CVSS
    5.4
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.13 %
    percentile 3.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. Act now Wordfence

    Meow Gallery

    CVE-2026-15386

    Affects you if you run Meow Gallery through 5.5.1 and users with the Author role or higher can publish posts on your site.

    Meow Gallery does not sufficiently escape an attachment's alt text before it is output in a linked gallery. This is stored cross-site scripting.

    An authenticated attacker with the Author role or higher can store arbitrary web scripts. They execute in the browser of every visitor who views a post containing the affected gallery, including an administrator.

    Update Meow Gallery to 5.5.2.

    Affected
    Meow Gallery
    Fixed in
    5.5.2
    CVSS
    5.4
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.13 %
    percentile 3.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. Act now Wordfence

    YMC Filter

    CVE-2026-16558

    Affects you if you run the YMC Filter WordPress plugin in a version up to and including 3.12.7 and have users with the Contributor role or higher.

    The plugin allows storing malicious code in a layout builder setting. When saving, it neither verifies that the user owns the object being edited nor sanitizes the input sufficiently. An attacker with a Contributor account can store JavaScript that executes in the browser of any visitor who accesses the affected page.

    The vulnerability is not exploitable from the outside without an account, but the barrier is low. Contributor is a default role in WordPress that many installations also assign to guest authors.

    Update YMC Filter to version 3.12.8.

    Affected
    YMC Filter
    Fixed in
    3.12.8
    CVSS
    5.4
    source 134c704f-9b21-4f2e-91b3-4a467353bcc0
    Login required
    yes, user account
    Likely to be exploited
    0.13 %
    percentile 3.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-08-03

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. Act now Wordfence

    ShopLentor Pro

    CVE-2026-61972

    Affects you if you run ShopLentor Pro up to and including version 2.8.5.

    A broken access control that can be exploited without logging in. An attacker can reach functions that should require an account. What exactly they do with that depends on which functions the plugin exposes in the vulnerable area. The source does not give a definitive list, but the hole opens the door to settings and data not meant for strangers.

    Update to version 2.8.6.

    Affected
    ShopLentor Pro
    Fixed in
    2.8.6
    CVSS
    5.3
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 12.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-01

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

182 checked and dismissed, with reasons
  • 118 advisoriesSteht nicht auf der Beobachtungsliste dieses Lagebilds. Entweder gehört das Produkt nicht zu den Bausteinen eines Webservers mit WordPress, oder es ist eine Bibliothek, deren Korrektur mit den regelmäßigen Updates der Distribution ohnehin eingespielt wird, ohne eigenen Handgriff. Meldungen, die mehr verlangen als das, stehen oben als eigener Eintrag.
  • 19 advisoriesDie Paketmeldung einer anderen Distribution, etwa Red Hat oder FreeBSD. Jede Distribution veröffentlicht dieselbe Lücke für ihre eigenen Pakete als eigene Meldung. Für Server mit Debian oder Ubuntu zählt die Meldung der eigenen Distribution, und die erscheint hier als eigener Vorgang, sobald sie ein beobachtetes Produkt trifft.
  • 17 advisoriesSoftware für Arbeitsplatzrechner und Telefone, Browser eingeschlossen. Sie gefährdet den Rechner, an dem Sie sitzen, nicht den Server, auf dem Ihre Seite läuft. Aktuell halten sollten Sie sie trotzdem, denn ein übernommener Arbeitsplatz gibt Angreifern oft die gespeicherten Zugänge zum Server preis. In dieses Serverlagebild gehört sie nicht.
  • 12 advisoriesNetzwerk- und Sicherheitsgeräte wie Firewalls und VPN-Zugänge. Sie stehen vor einem Firmennetz, nicht auf einem gemieteten Server, dort gehört diese Ebene dem Hoster. Wer ein solches Gerät im Büro stehen hat, sollte dessen Updates ernst nehmen, denn genau diese Geräteklasse wird derzeit besonders häufig aktiv angegriffen. Das ist aber ein anderes Lagebild.
  • 11 advisoriesGrafische Linux-Software für den Arbeitsplatz, etwa Bildbearbeitung, Medienbibliotheken oder der Druckdienst. Ein Webserver läuft ohne grafische Oberfläche, diese Pakete sind dort im Regelfall gar nicht installiert. Auf einem Linux-Arbeitsplatzrechner gilt dasselbe wie bei Browsern: aktuell halten, aber die Quelle dafür ist ein anderes Lagebild.
  • 10 advisoriesWindows-Servertechnik wie Exchange oder Active Directory. Auf einem Linux-Server mit WordPress ist davon nichts installiert, die beiden Welten teilen keinen Code. Wer zusätzlich eine Windows-Umgebung betreibt, braucht dafür eine eigene Beobachtung.
  • 10 advisoriesEine Programmiersprache samt Laufzeit, etwa Go oder Erlang. Eine Lücke dort erreicht einen Server nur über ein Programm, das in dieser Sprache geschrieben und dort installiert ist. WordPress und die übliche Serversoftware sind in PHP und C geschrieben, und was die Distribution selbst in Go ausliefert, meldet sie über ihre eigenen Sicherheitshinweise.
  • 6 advisoriesIBM-Unternehmenssoftware wie DB2 oder WebSphere. Sie läuft in Rechenzentren mit eigener Betriebsmannschaft, auf einem Linux-Webserver mit WordPress kommt sie nicht vor. Wer sie im Haus hat, bezieht die Hinweise dazu über den Wartungsvertrag.
  • CVE-2021-47378Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-5358GNU-libc-Meldung, die NVD als zurückgewiesen führt, weil die betroffene NIS+-Schnittstelle auf Linux nie ausgeliefert wurde und keine Vertrauensgrenze überschreitet.
  • CVE-2026-64561Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine, aus der Ferne ohne Anmeldung nicht ausnutzbar.
  • CVE-2026-16502Live Composer ist ein WordPress-Plugin mit geringer Verbreitung, und die Lücke erfordert ein angemeldetes Konto sowie eine zusätzlich installierte POP-Kette, ohne die sie keine Wirkung entfaltet.
  • CVE-2026-81766WordPress-Plugin, erfordert eine benutzerdefinierte Rolle und eine nicht standardmäßige Multisite-Konfiguration, die Reichweite ist zu klein.
  • CVE-2026-82226WordPress-Plugin, ohne Anmeldung auslösbar, aber ohne bekannte POP-Kette im Plugin selbst, die Auswirkung hängt von weiteren installierten Erweiterungen ab.
  • CVE-2023-53034Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38177Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-38236Linux-Kernel, Use-after-free über lokale Unix-Sockets. Die Ausnutzung erfordert bereits einen lokalen Prozess oder ein Konto und bietet keine entfernte Angriffsfläche.
  • CVE-2025-38353Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2024-58239Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50339Linux-Kernel, Fehler im Bluetooth-Stack. Betrifft nur Bluetooth-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-39891Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50556Linux-Kernel, Fehler im DRM-Treiber. Erfordert bereits ein Konto oder einen laufenden Prozess auf der Maschine.
  • CVE-2025-40029Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40086Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40110Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-40178Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50583Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-50712Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2022-42719Linux-Kernel, Fehler im WLAN-Stack. Betrifft nur WLAN-fähige Geräte, nicht den Webserver-Betrieb.
  • CVE-2025-68767Linux-Kernel, lokale Rechteausweitung, erfordert bereits ein Konto auf der Maschine.
  • CVE-2025-71102Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-31431Linux-Kernel, lokale Rechteausweitung. Erfordert bereits ein Konto auf der Maschine.
  • CVE-2026-0864CPython, Interpreter auf Servern vorinstalliert. Lücke erfordert Kontrolle über geschriebene Werte, nicht aus der Ferne auslösbar.