Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    WPFormify – Stripe Payments with Form and Checkout

    CVE-2026-6627

    Affects you if you use the WPFormify plugin in a version up to and including 1.1.1 and rely on Stripe for payments.

    An attacker can overwrite your site’s Stripe credentials or disconnect the Stripe integration entirely, without logging in. The functions that allow this are hooked to a call that is reachable without authentication. Overwriting the credentials redirects incoming payments to the attacker’s Stripe account. This is direct revenue loss, not a theoretical scenario.

    Update to version 1.1.2 and check your Stripe settings in the plugin to verify that your own credentials are still stored there.

    Affected
    WPFormify – Stripe Payments with Form and Checkout
    Fixed in
    1.1.2
    CVSS
    8.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.62 %
    percentile 46.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    TableOn

    CVE-2026-18881

    Affects you if you run the TableOn plugin in any version up to and including 1.0.5.1 and the table is publicly reachable. Out of the box, the plugin is accessible without logging in.

    A blind SQL injection through the comment_count parameter. The value is split on a colon and both halves are inserted into a database query unchecked. An attacker can append their own queries without an account and extract information from the database. Blind means the result is not shown directly, but it can still be determined through timing differences or error patterns.

    The plugin is not a core component, but the vulnerability is reachable from the outside and requires no login. That is why it is immediate.

    Update to version 1.0.6. The source does not provide a workaround.

    Affected
    TableOn – WordPress Posts Table Filterable 
    Fixed in
    1.0.6
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.38 %
    percentile 30.4
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Dokan

    CVE-2026-8761

    Affects you if you run the Dokan plugin for WooCommerce in a version up to and including 5.0.2 and have registered users with the Vendor role or higher on your site.

    A missing authorization check in the plugin's REST API. An authenticated attacker with a vendor account can read, modify, or delete users from the database. That includes administrator accounts. The attacker needs an account, but only that of a simple vendor.

    Update Dokan to version 5.0.3.

    Affected
    Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
    Fixed in
    5.0.3
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.37 %
    percentile 29.7
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    AI Copilot – Content Generator

    CVE-2026-6639

    Affects you if you use the AI Copilot – Content Generator plugin in a version up to and including 1.4.6 and utilize features like the Bulk Post Generator.

    The plugin exposes task parameters that are not meant for outside eyes. An unauthenticated attacker can retrieve the results of running tasks because the responsible controller performs no authorization check. Among the parameters is the OpenAI API key in plaintext. Whoever holds that key can use the language model at your expense.

    Update to version 1.4.19. Then replace the OpenAI API key, as it may already have been compromised.

    Affected
    AI Copilot – Content Generator
    Fixed in
    1.4.19
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.37 %
    percentile 29.6
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. For the record Wordfence

    Cost Calculator Builder

    CVE-2026-7753

    Affects you if you run the Cost Calculator Builder WordPress plugin in a version up to and including 3.6.17 and users with the Subscriber role or higher have backend access.

    The plugin exports every calculator's full configuration at the push of a button. The check whether the user is allowed to do that is missing. Instead, the code relies on a security token that it delivers on every backend page, including to Subscribers. An attacker with a Subscriber account can read out all calculators.

    Update to a version after 3.6.17. The source does not name the exact version that contains the fix.

    Affected
    Cost Calculator Builder
    Fixed in
    4.0.3
    CVSS
    6.5
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.36 %
    percentile 28.3
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. For the record Wordfence

    wiseCampaign

    CVE-2026-7529

    Affects you if you have the wiseCampaign plugin installed on your WordPress site in a version up to and including 1.1.16.

    Every REST endpoint of the plugin is reachable without authentication or capability check. An attacker can read and modify the entire plugin configuration, swap banners and background images, and toggle features on and off. This is not a subtle attack; it is a wide-open barn door.

    Update to version 1.1.17 and check the plugin settings and uploaded banner files for unwanted changes.

    Affected
    wiseCampaign – WooCommerce Conversions Made Easy
    Fixed in
    1.1.17
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.35 %
    percentile 27.9
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. For the record Wordfence

    Smart Popup by Supsystic

    CVE-2026-18322

    Affects you if you run the WordPress plugin Smart Popup by Supsystic in a version up to and including 1.12.0.

    An unauthenticated privilege escalation. A flaw in the plugin's permission check allows calling the protected user creation action. The required nonce is also leaked in the subscriber confirmation email. Combined with a missing role check, a stranger can register themselves as an administrator.

    Update to version 1.13.0. Then check your user list for unknown administrators.

    Affected
    Smart Popup by Supsystic
    Fixed in
    1.13.0
    CVSS
    8.8
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.31 %
    percentile 23.9
    Type
    CWE-269
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. For the record Wordfence

    Membership Plugin – Kadence Memberships

    CVE-2026-9273

    Affects you if you run the Kadence Memberships plugin in versions up to and including 4.0.0 and use the legacy [login_form] shortcode on a public page.

    A stranger can redirect the password reset link to an address they control. The plugin trusts a parameter the attacker sends along with the form submission and builds the link it mails to the user from it. If the user clicks it, they land on the foreign page and enter their new password there without noticing. The attacker takes over the account.

    The hole sits in an old function reachable only through the [login_form] shortcode. If you use the plugin without that shortcode, you are not affected.

    Update to version 4.0.1. Remove the [login_form] shortcode from all public pages if you cannot apply the update immediately.

    Affected
    Membership Plugin – Kadence Memberships
    Fixed in
    4.0.1
    CVSS
    9.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.28 %
    percentile 19.9
    Type
    CWE-640
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. For the record Wordfence

    MailChimp Forms by MailMunch

    CVE-2026-7520

    Affects you if you use the MailChimp Forms by MailMunch plugin in a version up to and including 3.2.7 and users with the subscriber role or higher have access to your installation.

    The sign-in and sign-up AJAX actions do not check whether the user has the necessary capabilities. An attacker with a subscriber-level account can relink the plugin's integration to their own MailMunch credentials. From then on, all new sign-ups through your forms go to their account, and the forms and landing pages displayed on your site are pulled from their MailMunch account.

    Update to version 3.2.8.

    Affected
    Mailmunch Forms for Mailchimp
    Fixed in
    3.2.8
    CVSS
    8.1
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.27 %
    percentile 19.0
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. For the record Wordfence

    Layouts for WPBakery

    CVE-2026-7726

    Affects you if you run the Layouts for WPBakery plugin in any version up to and including 1.1.3.

    An unauthenticated attacker can abuse the `handle_sync` AJAX action to force your server to repeatedly fetch data from an external server and store it in the database without verification. This does not give direct access to your content, but the ability to fill the database with foreign data opens avenues for abuse, such as degrading site performance or consuming storage.

    Update to version 1.1.4.

    Affected
    Layouts for WPBakery
    Fixed in
    1.1.4
    CVSS
    6.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 18.7
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-08-04

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.