Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Cybersecurity · August 29, 2026

Cybersecurity·thehackernews.com

Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes — including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — that together could let attackers bypass authentication, take over accounts, or run arbitrary code on affected sites. One of the flaws, tracked as CVE-2026-76581, scored a near-maximum 9.8 on the CVSS scale. Site owners running any of these plugins or themes should update to the patched versions without delay.

// source: thehackernews.com ↗

Back to Blog