logo

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

ID: 2dfba54b-7ef8-585d-9c9b-b3fc835623d5

STIX ID: report--2dfba54b-7ef8-585d-9c9b-b3fc835623d5

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-29

Date Updated: 2026-08-30

Author: [email protected] (The Hacker News)

...
...

Multiple critical vulnerabilities were disclosed in several widely used WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—potentially allowing unauthenticated attackers to bypass authentication, perform arbitrary file writes and remote code execution, expose administrator password-reset data for account takeover, or escalate privileges to administrator. The report lists CVE IDs and high CVSS scores (9.8–10.0), affected versions, and technical commentary from Wordfence and Patchstack highlighting root causes such as unsafe unserialize usage and shipped development libraries that enable gadget chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.