BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical WordPress plugin flaws allow site takeover, RCE

Five critical WordPress flaws enable site takeover via authentication bypass and code execution.

  • Five critical vulnerabilities in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, could allow attackers to take over sites completely.
  • Two of the flaws, CVE-2026-76581 in WPMU DEV Dashboard and CVE-2026-18431 in Avada, score 9.8 on the CVSS scale and enable authentication bypass and remote code execution without any prior access.
  • The most severe vulnerability, CVE-2026-82222 in GiveWP, carries a perfect 10.0 CVSS score and exploits a broken unserialize function to achieve command execution on the server.

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below.

- Advertisement -

A critical authentication bypass flaw in the WPMU DEV Dashboard plugin, tracked as CVE-2026-76581, allows an unauthenticated attacker to obtain administrator access and achieve site takeover. This affects all plugin versions up to and including 5.0.1 when Hub Single-Sign On is enabled and mapped to an administrator.

Meanwhile, a remote code execution vulnerability in the Avada theme, CVE-2026-18431, enables an unauthenticated attacker to write malicious files and execute arbitrary PHP code. The flaw impacts Avada versions up to 7.16 when the Fusion Builder plugin is active in versions up to 3.16.

Another critical issue, CVE-2026-19632 in the TranslatePress plugin, exposes raw administrator password-reset URLs, enabling full account takeover. This affects plugin versions up to 3.3.1 only when automatic string saving is enabled and the target administrator’s locale is set to a published secondary language.

A privilege escalation flaw in the Pods plugin, CVE-2026-19598, allows an unauthenticated attacker to gain administrator privileges or overwrite any user password. The vulnerability affects all Pods versions up to and including 3.3.9.

- Advertisement -

The most severe vulnerability, CVE-2026-82222 in the GiveWP plugin, carries a CVSS score of 10.0 and enables arbitrary command execution. Patchstack explained that the flaw chains a broken safe unserialize helper, a donation flow feeding attacker-controlled data, and a gadget chain in code that GiveWP ships. “This case shows how PHP object injection turns into remote code execution when three ingredients line up: a place to store an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded classes.” The vulnerability affects GiveWP versions up to 4.16.7.1.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

REX Launches 2x Leveraged ETF on Bitcoin Treasury Strive

REX Shares and Tuttle Capital Management launched the ASSX ETF on Cboe, offering 2x...

Senate Clarity Act fails 49-50; crypto regulation shifts to agencies

The Senate failed to advance the Clarity Act in a 49-50 vote, with Democrats...

Bitcoin Rebounds Above $80K as Rare Bullish Signal Emerges

Bitcoin rebounded above $81,000 after briefly dipping to $76,000, with a rare monthly technical...

Bernstein predicts Nvidia stock surge to $400

NVIDIA stock closed at $222 after rising 1.34% on Friday, with analysts now projecting...

Solana cuts block slot to 250ms, eyes 200ms next

Solana reduced its target slot time from 300 milliseconds to 250 milliseconds on Friday,...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading