Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Relevanssi
CVE-2026-15941Affects you if you run Relevanssi or Relevanssi Premium and users with the Contributor role or higher have access to the WordPress dashboard.
A SQL injection through the plugin's admin search. An attacker with a Contributor account can use it to blindly read data from the database. The attack takes time because the database response is not directly visible but must be inferred through time delays.
The vulnerability is not on the KEV catalog of actively exploited flaws. A Contributor account is the prerequisite. That makes a mass attack unlikely, but it is suitable for a targeted attack on an installation where an attacker already has such an account.
Update Relevanssi to 4.27.2 or Relevanssi Premium to 2.30.3.
- Affected
- Relevanssi Premium – A Better Search, Relevanssi – A Better Search
- Fixed in
- 2.30.3, 4.27.2
- CVSS
- 6.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.25 %
percentile 16.3 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Smash Balloon Social Photo Feed
CVE-2026-15452Affects you if you run the Smash Balloon Social Photo Feed plugin in a version up to and including 6.11.3.
A reflected cross-site scripting vulnerability. An attacker can place malicious code in the address bar. To do so, they need to trick someone with access to the site into clicking a crafted link. If that succeeds, the victim's browser executes the script as if it came from your site.
The vulnerability is not listed in the CISA KEV catalog of actively exploited flaws. No active attack is currently known. That justifies the informational rating.
Update to version 6.11.4.
- Affected
- Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
- Fixed in
- 6.11.4
- CVSS
- 4.7
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 15.1 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
VikRentItems Flexible Rental Management System
CVE-2026-16143Affects you if you run the VikRentItems Flexible Rental Management System plugin in a version up to and including 1.2.1 and the guest booking form is enabled.
An attacker can place a booking without an account and inject malicious code into the email field. The code is stored and later executed in the admin area as soon as someone views the booking. This is a classic stored XSS that enters through an insufficiently sanitized form field.
The vulnerability is not critical because it requires interaction in the backend and the likelihood of exploitation is low. It is still listed here because it works without authentication and may appear on the managed systems.
Update to version 1.2.2.
- Affected
- VikRentItems Flexible Rental Management System
- Fixed in
- 1.2.2
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.24 %
percentile 14.7 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Independent Analytics
CVE-2026-17506Affects you if you run the Independent Analytics plugin in a version up to and including 2.15.0.
An attacker can store malicious code in the analytics data without logging in. The code executes as soon as someone with the right permissions views the 404 statistics in the dashboard. The plugin sanitizes the submitted URLs in the wrong order, so a harmless-looking address turns into active HTML when displayed.
Update to version 2.15.1.
- Affected
- Independent Analytics – WordPress Analytics Plugin
- Fixed in
- 2.15.1
- CVSS
- 7.2
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.23 %
percentile 13.9 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Football Pool
CVE-2026-8790Affects you if you run the WordPress plugin Football Pool in a version up to and including 2.13.4 and use the Shoutbox widget.
A reflected cross-site scripting in the Shoutbox widget. An attacker can craft a link or a page that sends a POST request to your site. If the security check fails, the injected code is echoed back into a logged-in visitor's browser without filtering. The attacker does not need an account for this, but they do need to trick someone who has one into submitting the manipulated request. That limits the immediate danger, which is why I am only noting this report.
Update to version 2.13.5.
- Affected
- Football Pool
- Fixed in
- 2.13.5
- CVSS
- 6.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.22 %
percentile 12.6 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Contact Form Extender for Divi
Wordfence advisoryAffects you if you run the Contact Form Extender for Divi plugin in a version up to and including 1.0.6 on your WordPress site.
A plugin for the Divi theme that can delete files on the server without the attacker being logged in. The file path validation is insufficient. An attacker can use this to delete arbitrary files, such as wp-config.php. That opens the door to a full site takeover.
Update to version 1.0.7.
- Affected
- Contact Form Extender for Divi – Submissions DB & Extra Fields
- Fixed in
- 1.0.7
- CVSS
- 7.5
source Wordfence - Actively exploited
- not on the KEV list
- Published
- 2026-08-04
Sources: Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Online Scheduling and Appointment Booking System – Bookly
CVE-2026-13395Affects you if you run Bookly in a version before 27.8 and the booking page is reachable from outside. It is, if you take appointments online.
A SQL injection in the booking flow. A stranger can append parameters to the query without logging in and read the database. Password hashes are the least of what comes out. The flaw is not on the KEV list, but exploitation is simple and the plugin is widely deployed.
Update to version 27.8 or newer. No workaround is known, only the update helps.
- Affected
- Online Scheduling and Appointment Booking System – Bookly
- Fixed in
- 27.8
- CVSS
- 8.6
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- no
- Likely to be exploited
- 0.34 %
percentile 26.5 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
MotoPress Hotel Booking
CVE-2026-15235Affects you if you run MotoPress Hotel Booking in a version below 6.0.4 and allow users with low privileges, such as subscribers, to be created on your installation.
An AJAX endpoint in the plugin returns a booking's full customer details without first checking whether the requester is authorized to see them. Any authenticated user, even a subscriber, can retrieve your customers' names, email addresses, phone numbers, and physical addresses. A data leak through the back door that requires no active exploitation, just an account.
The vulnerability is not listed in the CISA KEV catalog of actively exploited vulnerabilities. That does not make it harmless, but there is currently no indication of ongoing attacks.
Update to version 6.0.4.
- Affected
- MotoPress Hotel Booking
- Fixed in
- 6.0.4
- CVSS
- 4.3
source 134c704f-9b21-4f2e-91b3-4a467353bcc0 - Login required
- yes, user account
- Likely to be exploited
- 0.22 %
percentile 13.1 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-08-03
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now Wordfence
ShopLentor Pro
CVE-2026-61972Affects you if you run ShopLentor Pro up to and including version 2.8.5.
A broken access control that can be exploited without logging in. An attacker can reach functions that should require an account. What exactly they do with that depends on which functions the plugin exposes in the vulnerable area. The source does not give a definitive list, but the hole opens the door to settings and data not meant for strangers.
Update to version 2.8.6.
- Affected
- ShopLentor Pro
- Fixed in
- 2.8.6
- CVSS
- 5.3
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.21 %
percentile 11.9 - Type
- CWE-862
- Actively exploited
- not on the KEV list
- Published
- 2026-08-01
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Wordfence
CubeWP Framework
CVE-2026-13339Affects you if you use the CubeWP Framework plugin and its posts shortcode or widget is rendered on a page with AJAX loading enabled.
A directory traversal flaw that lets anyone read arbitrary files without logging in. The plugin emits a security token into the page markup, so any visitor can read it. That defeats the protection meant to keep people from opening files outside the intended directory. The result is read access to configuration files and other sensitive data on the server.
Update the plugin to the latest version and check whether AJAX loading for the widget or shortcode is still necessary.
- Affected
- CubeWP Framework
- Fixed in
- 1.1.31
- CVSS
- 7.5
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.64 %
percentile 47.4 - Type
- CWE-22
- Actively exploited
- not on the KEV list
- Published
- 2026-08-01
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.