#3
The Hacker News
general
August 29, 2026 at 16:25 UTC
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
By [email protected] (The Hacker News)
AI Summary
Critical vulnerabilities were disclosed across five widely-used WordPress plugins and themes — WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — with flaws including CVE-2026-76581 (CVSS 9.8), an authentication bypass enabling full site takeover, as well as additional RCE vulnerabilities reported by Wordfence and Patchstack. These flaws collectively put millions of WordPress installations at risk of unauthenticated account takeover and arbitrary code execution. WordPress administrators should apply available patches immediately and audit for signs of exploitation.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →