Threat Log
Nothing in the entire threat log matches that search. Try a shorter term, for example just the product name or the CVE number.
-
For the record Wordfence
Kali Forms
CVE-2026-16144Affects you if you run the Kali Forms plugin in any version up to and including 2.4.20 and at least one form contains a field named thisPermalink, entryCounter, or submission_link. You can check that in the form editor.
An attacker can execute their own code on your server without logging in. All it takes is submitting a form that contains one of the reserved fields. The plugin's own safeguard only checks whether the placeholders have changed, not whether they come from the outside. A trusted call is fed with attacker data.
The vulnerability is not on the KEV list and the EPSS likelihood sits at 0.7 percent. That argues against widespread exploitation. Still, act now: if you run a form with the named fields, you have an open door on your system.
Update to version 2.4.21. The source names no workaround that avoids the update.
- Affected
- Kali Forms — Contact Form & Drag-and-Drop Builder
- Fixed in
- 2.4.21
- CVSS
- 8.1
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.69 %
percentile 49.4 - Type
- CWE-94
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Single Sign On For TNG
CVE-2026-15964Affects you if you run the WordPress plugin Single Sign On For TNG in any version up to and including 2.0.0.
A plugin that lets people skip the login. A stranger can reset the password of any user without credentials and then sign in as that user, administrator included. The function that does this is reachable without authentication and does not check whether the request comes from the legitimate account owner.
Update to the next available version that closes this hole. If none exists yet, disable the plugin until the update ships.
- Affected
- Single Sign On For TNG
- Fixed in
- 2.1.0
- CVSS
- 9.8
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.49 %
percentile 39.6 - Type
- CWE-620
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Subscriptions for WooCommerce
CVE-2026-15414Affects you if you run Subscriptions for WooCommerce up to and including version 2.0.0 and users with the Contributor role or higher have backend access.
A Contributor can promote themselves to Administrator. The plugin saves a user role from the form when editing a membership plan, without checking whether the sender is allowed to assign that role. The only restriction in the form is a grayed-out field that can be overwritten using the browser's developer tools. The server accepts the value and writes it to the database.
Update to a version that closes this vulnerability. If no update is available, check the user list for administrators you did not create.
- Affected
- Subscriptions for WooCommerce
- Fixed in
- 2.0.1
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.34 %
percentile 26.2 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
PixelYourSite
CVE-2026-18059Affects you if you run PixelYourSite up to 11.2.1 in a WooCommerce shop and the order received page is reachable, whether visitors are logged in or not.
The plugin writes sensitive order data into the page source of the order received page as soon as it sees an order ID in the URL. It does not check whether the visitor actually owns that order. An attacker can cycle through order IDs and pull product names, quantities, per-item prices, order totals, and transaction IDs.
No account is required. The hole is exploitable remotely with nothing more than a guessable or enumerated order ID.
Update to 11.2.2 or 12.6.1. The source provides no workaround that replaces taking the order received page offline.
- Affected
- PixelYourSite Pro – Your smart PIXEL (TAG) Manager, PixelYourSite – Your smart PIXEL (TAG) & API Manager
- Fixed in
- 11.2.2, 12.6.1
- CVSS
- 5.3
source security@wordfence.com - Login required
- no
- Likely to be exploited
- 0.33 %
percentile 25.8 - Type
- CWE-200
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Pronamic Pay
CVE-2026-16635Affects you if you run Pronamic Pay up to and including version 10.1.0 and use Gravity Forms with a user role update field. An attacker needs an account, even just a subscriber account.
An attacker with a basic account can make themselves an administrator. The function that sets the role does not check which roles are allowed. It takes the value from the form and writes it directly into the user record. An administrator must have set up the Gravity Forms connection beforehand, otherwise the vulnerability leads nowhere.
The vulnerability is not on the KEV list and the likelihood of exploitation is 0.3 percent. It is still here because it applies to my systems and an attacker gains administrator rights with a single form submission.
Update to version 10.2.0. The source names no workaround; only the update helps.
- Affected
- Pronamic Pay
- Fixed in
- 10.2.0
- CVSS
- 8.8
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.31 %
percentile 23.3 - Type
- CWE-269
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
W3 Total Cache
CVE-2026-66695Affects you if you run W3 Total Cache in a version up to and including 2.10.2. The vulnerability is triggerable without authentication.
A path traversal that works without logging in. An attacker can access files outside the intended directory, including configuration files with credentials or other sensitive content. W3 Total Cache is widely deployed, so the attack surface is large.
Update to version 2.10.3. The source does not name a workaround.
- Affected
- W3 Total Cache
- Fixed in
- 2.10.3
- CVSS
- 6.5
source audit@patchstack.com - Login required
- no
- Likely to be exploited
- 0.27 %
percentile 19.3 - Type
- CWE-35
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Icegram Engage
CVE-2026-16087Affects you if you run Icegram Engage in versions up to and including 3.1.42 and have registered users with at least the Contributor role.
A SQL injection that works in two steps. An attacker with a Contributor account or higher stores a crafted value that initially looks harmless. During a later database query, that value is inserted into a SQL statement without checking and gets executed. This allows the attacker to read the database.
The vulnerability requires an account, but Contributor is the lowest writing role in WordPress. Many installations hand it out to guests or customers. That makes the hole relevant for those systems.
Update to the version that Wordfence lists as fixed. The source does not name a specific version number.
- Affected
- Icegram Engage – Popups, Optins, CTAs & Lead Generation
- Fixed in
- 3.1.43
- CVSS
- 6.5
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.27 %
percentile 18.9 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
GSheetConnector
CVE-2026-16614Affects you if you run the GSheetConnector plugin in version 5.2.1 or older and an attacker has access to an administrator account.
A SQL injection in the administration interface. An attacker with administrator privileges can append their own database commands to existing queries via the 's' parameter, extracting sensitive information from the database. The damage is limited to what an administrator could already see or export.
The vulnerability exists because wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters. Single quotes and other metacharacters remain in the parameter and become part of the query.
Update to version 5.2.2.
- Affected
- GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database
- Fixed in
- 5.2.2
- CVSS
- 4.9
source security@wordfence.com - Login required
- yes, administrator
- Likely to be exploited
- 0.27 %
percentile 18.7 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Download Manager
CVE-2026-16685Affects you if you run the Download Manager plugin in a version up to and including 3.3.66 and have at least one user with the Contributor role or higher.
An attacker with a Contributor account can store a script in a shortcode attribute. The plugin sanitizes the post content on save, but not the shortcode attribute values. When the page is loaded, the script executes in the browser of other visitors, including administrators. The attacker needs an account, but not a highly privileged one.
Update to version 3.3.67. The source does not mention another workaround.
- Affected
- Download Manager
- Fixed in
- 3.3.67
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.24 %
percentile 15.3 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
For the record Wordfence
Advanced Woo Labels
CVE-2026-15662Affects you if you run Advanced Woo Labels up to and including version 2.48 and have users with the Contributor role or higher.
An attacker with a Contributor account can store malicious code in the database via the bg_color parameter. The code runs in the browser of every visitor who opens the affected page. On its own this is annoying but not critical, because the attacker already needs an account.
The vulnerability is not on the KEV catalog of actively exploited vulnerabilities. That matches the low EPSS of 0.2 percent. I rate it for awareness, because a Contributor account is the hurdle and no active mass exploitation is known.
Update to version 2.49.
- Affected
- Advanced Woo Labels – Product Labels & Badges for WooCommerce
- Fixed in
- 2.49
- CVSS
- 6.4
source security@wordfence.com - Login required
- yes, user account
- Likely to be exploited
- 0.24 %
percentile 14.5 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-07-31
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
383 checked and dismissed, with reasons
- 169 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 7 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 4 advisoriesKein Java-Anwendungsserver im Bestand.
- 3 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 3 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 2 advisoriesBetreibt unter meinen Kunden niemand.
- CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
- CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
- CVE-2024-58022Lokaler NULL-vs-IS_ERR-Bug im Mailbox-Treiber, hardware-spezifisch und ohne Fernausnutzung.
- CVE-2025-32462Betrifft nur eine seltene sudoers-Konfiguration mit explizitem Hostnamen, die auf Georges Servern nicht vorkommt, und ist nicht aktiv ausgenutzt.
- CVE-2020-26145Betrifft WLAN-Firmware eines Samsung-Smartphones, nicht den Serverbetrieb.
- CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
- CVE-2025-38731Lokale Kernel-Schwachstelle im DRM-Treiber, nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
- CVE-2025-39736Lokaler Deadlock im Kernel, kein Datenabfluss, nicht aktiv ausgenutzt.
- CVE-2022-49202Lokale Kernel-Schwachstelle im Bluetooth-Treiber, nicht auf Servern relevant.
- CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
- CVE-2025-40025Lokaler Bug im f2fs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht eingesetzt wird.
- CVE-2025-40086Lokaler Bug im GPU-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne dedizierte Grafikkarten.
- CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
- CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
- CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
- CVE-2022-50697Lokale Kernel-Schwachstelle im MRP-Protokoll, nicht ohne Konto ausnutzbar.
- CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
- CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
- CVE-2025-71145Lokale Kernel-Schwachstelle im USB-PHY-Treiber, nicht auf Servern relevant.
- CVE-2025-71200Lokaler Bug im MMC-Treiber, hardware-spezifisch und ohne Relevanz für Server ohne MMC-Hardware.
- CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
- CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
- CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
- CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
- CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.