Home / Aug 31, 2026 / Story
0
#3 The Hacker News general August 29, 2026 at 16:25 UTC

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

By [email protected] (The Hacker News)

AI Summary

Critical vulnerabilities were disclosed across five widely-used WordPress plugins and themes — WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — with flaws including CVE-2026-76581 (CVSS 9.8), an authentication bypass enabling full site takeover, as well as additional RCE vulnerabilities reported by Wordfence and Patchstack. These flaws collectively put millions of WordPress installations at risk of unauthenticated account takeover and arbitrary code execution. WordPress administrators should apply available patches immediately and audit for signs of exploitation.

Relevance score: 85.0/100

# More from August 31