Threat Log

544advisories read
161affect you
383checked and dismissed
As of

Updated every 6 hours
10 of 161 entries
  1. For the record Wordfence

    User Access Manager

    CVE-2026-18352

    Affects you if you run the User Access Manager plugin in any version up to and including 2.3.15.

    The plugin is meant to control access to files. A flaw in how it handles the 'uamgetfile' parameter allows an attacker to bypass this control with a trick. By combining a valid attachment ID with a manipulated file path, an unauthenticated attacker can read arbitrary files on the server. The permission check passes against the legitimate public attachment, but the file streamed is the one the attacker specified in the path.

    Configuration files containing credentials or other sensitive information can be read. Read access to the filesystem is often the first step toward a full takeover.

    Update to the next available version after 2.3.15 or deactivate the plugin until the update is applied.

    Affected
    User Access Manager
    Fixed in
    2.3.16
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.68 %
    percentile 48.9
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-08-01

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    WooCommerce - Social Login

    CVE-2026-8457

    Affects you if you run the WooCommerce - Social Login plugin in versions up to and including 2.8.7 with Apple login enabled.

    The plugin does not verify the signature of the token it receives during Apple login. It decodes the payload and accepts it blindly. At the same time, the security nonce required to trigger the login flow sits in plain sight for any unauthenticated visitor in the JavaScript on the login page.

    An attacker can craft a forged token and sign in as any existing user, administrator included, with no password.

    Update the plugin to version 2.8.8.

    Affected
    WooCommerce - Social Login
    Fixed in
    2.8.8
    CVSS
    9.8
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.40 %
    percentile 33.0
    Type
    CWE-289
    Actively exploited
    not on the KEV list
    Published
    2026-08-01

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. Act now Wordfence

    Bit integrations

    CVE-2026-15006

    Affects you if you use the WordPress plugin Bit integrations in a version up to and including 2.9.0 and have the Contact Form 7 File Upload field enabled.

    An attacker can read arbitrary files on the server without logging in. The flaw is in how file attachments uploaded through an optional Contact Form 7 field are processed. What passes as a harmless file can be a path that reads out the system. Configuration files, credentials, anything the web server can read is reachable.

    Update to version 2.9.1. The source provides no workaround that closes the hole without the update.

    Affected
    Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation
    Fixed in
    2.9.1
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.83 %
    percentile 54.4
    Type
    CWE-22
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. Act now Wordfence

    FormGent

    CVE-2026-3141

    Affects you if you use the FormGent WordPress plugin in versions up to and including 1.9.2.

    A REST endpoint in the plugin is missing a capability check. An attacker with no account can delete files in the plugin's upload directory. On Linux servers where the wp-content/uploads/formgent directory does not yet exist – which is the default state right after installation – the path traversal protection can be bypassed. That makes files outside that directory reachable.

    Update to version 1.10.0.

    Affected
    FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
    Fixed in
    1.10.0
    CVSS
    9.1
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.47 %
    percentile 38.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Wordfence

    Database Collation Fix

    CVE-2026-15018

    Affects you if you run the Database Collation Fix plugin in a version up to and including 1.2.10 and the file trigger.txt exists in the plugin directory. The file is created by certain DesktopServer integration events.

    An SQL injection that requires no login. An attacker can append their own database queries to existing queries via the force-collation-algorithm parameter and extract contents from the database. The prerequisite is that the file trigger.txt sits in the plugin folder. That happens during DesktopServer integration events, such as site creation. If the file is not there, the vulnerability goes nowhere.

    The CVSS of 5.3 is misleading. It reflects the trigger file condition, not what follows after the database is read. Whoever has access to the database has access to everything in it. That is why this entry is here and not in the filter.

    Remove the plugin or update to version 1.2.11. Then delete the trigger.txt file if it exists and check the database for unknown queries.

    Affected
    Database Collation Fix
    Fixed in
    1.2.11
    CVSS
    5.3
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.27 %
    percentile 18.3
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  6. Act now Wordfence

    MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder

    CVE-2026-15052

    Affects you if you run the plugin MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder in a version up to and including 4.3.3.

    An attacker can store scripts in form fields without logging in. The scripts execute in the browser of anyone visiting the affected page. This ranges from redirecting visitors to external sites to stealing an administrator's session data.

    Update to version 4.3.4.

    Affected
    MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder
    Fixed in
    4.3.4
    CVSS
    7.2
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.24 %
    percentile 15.3
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  7. Act now Wordfence

    Jeg Kit for Elementor

    CVE-2026-2916

    Affects you if you run Jeg Kit for Elementor up to and including version 3.1.1 and users with at least Contributor access can edit posts.

    The plugin writes a full inventory of all installed plugins, system information, and in some cases API keys into a JavaScript variable on the post edit page. Anyone who can edit a post can read this data in plain text. An attacker with a Contributor account can see which other plugins are running in which version and whether usable keys like the Mailchimp API key are exposed.

    Update to version 3.1.2.

    Affected
    Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
    Fixed in
    3.1.2
    CVSS
    4.3
    source security@wordfence.com
    Login required
    yes, user account
    Likely to be exploited
    0.22 %
    percentile 12.3
    Type
    CWE-200
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  8. This week Wordfence

    WooCommerce PayPal Payments

    CVE-2025-14073

    Affects you if you run WooCommerce PayPal Payments in version 3.3.2 or older and process orders through your shop.

    A missing check at a point that displays order data. Without login, someone can reach order information via a sequential number, including the order key. With that key, full customer details can be retrieved within 10 minutes of order placement: name, email, phone, address.

    This is not a hole that wrings the password from your server. But it exposes every purchase, and whoever collects customer data does not need long to turn it into profit.

    Update the plugin to the latest version and check whether there have been unusual accesses to order data in the last few days.

    Affected
    WooCommerce PayPal Payments
    Fixed in
    3.4.0
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.23 %
    percentile 14.1
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  9. This week Wordfence

    User Profile Picture

    CVE-2026-61971

    Affects you if you use the User Profile Picture plugin in a version up to and including 2.6.3 and your installation has users with the Author role or higher whom you do not fully trust.

    An insecure direct object reference. An authenticated user with at least Author privileges can manipulate the user ID in a request and change another user's profile picture. On its own not a critical intervention, but an unwanted access to someone else's data that should not happen in a multi-author environment.

    Update to version 2.6.4.

    Affected
    User Profile Picture
    Fixed in
    2.6.4
    CVSS
    2.7
    source audit@patchstack.com
    Login required
    yes, administrator
    Likely to be exploited
    0.19 %
    percentile 9.1
    Type
    CWE-639
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  10. This week Wordfence

    Auto Featured Image (Auto Post Thumbnail)

    CVE-2026-61970

    Affects you if you run the Auto Featured Image plugin in a version up to and including 5.0.4 and have users with the Contributor role or higher.

    An attacker with a Contributor account can make the plugin send requests to internal services that are not reachable from the outside. That is enough to map the infrastructure behind the website or to talk to other unpatched services. On its own, the vulnerability relies on the reach of a restricted account, hence the rating for this week.

    Update to version 5.0.5. The source does not name a workaround.

    Affected
    Auto Featured Image (Auto Post Thumbnail)
    Fixed in
    5.0.5
    CVSS
    4.9
    source audit@patchstack.com
    Login required
    yes, user account
    Likely to be exploited
    0.12 %
    percentile 2.1
    Type
    CWE-918
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

383 checked and dismissed, with reasons
  • 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 4 advisoriesKein Java-Anwendungsserver im Bestand.
  • 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
  • CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
  • CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
  • CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
  • CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.