BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical WordPress plugin flaws allow site takeover, RCE

Five critical WordPress flaws enable site takeover via authentication bypass and code execution.

  • Five critical vulnerabilities in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, could allow attackers to take over sites completely.
  • Two of the flaws, CVE-2026-76581 in WPMU DEV Dashboard and CVE-2026-18431 in Avada, score 9.8 on the CVSS scale and enable authentication bypass and remote code execution without any prior access.
  • The most severe vulnerability, CVE-2026-82222 in GiveWP, carries a perfect 10.0 CVSS score and exploits a broken unserialize function to achieve command execution on the server.

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below.

- Advertisement -

A critical authentication bypass flaw in the WPMU DEV Dashboard plugin, tracked as CVE-2026-76581, allows an unauthenticated attacker to obtain administrator access and achieve site takeover. This affects all plugin versions up to and including 5.0.1 when Hub Single-Sign On is enabled and mapped to an administrator.

Meanwhile, a remote code execution vulnerability in the Avada theme, CVE-2026-18431, enables an unauthenticated attacker to write malicious files and execute arbitrary PHP code. The flaw impacts Avada versions up to 7.16 when the Fusion Builder plugin is active in versions up to 3.16.

Another critical issue, CVE-2026-19632 in the TranslatePress plugin, exposes raw administrator password-reset URLs, enabling full account takeover. This affects plugin versions up to 3.3.1 only when automatic string saving is enabled and the target administrator’s locale is set to a published secondary language.

A privilege escalation flaw in the Pods plugin, CVE-2026-19598, allows an unauthenticated attacker to gain administrator privileges or overwrite any user password. The vulnerability affects all Pods versions up to and including 3.3.9.

- Advertisement -

The most severe vulnerability, CVE-2026-82222 in the GiveWP plugin, carries a CVSS score of 10.0 and enables arbitrary command execution. Patchstack explained that the flaw chains a broken safe unserialize helper, a donation flow feeding attacker-controlled data, and a gadget chain in code that GiveWP ships. “This case shows how PHP object injection turns into remote code execution when three ingredients line up: a place to store an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded classes.” The vulnerability affects GiveWP versions up to 4.16.7.1.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Druckenmiller Sells Micron, Intel, Broadcom, Buys AMD

Stanley Druckenmiller exited positions in Micron, Intel, and Broadcom by Q2 end, moving capital...

Bitcoin’s oldest coins awaken in 2026 as $40M shifts

Galaxy Research data shows Bitcoin's oldest cohort—coins dormant for a decade or more—stirring more...

Wall Street Veteran Predicts Bitcoin at $600K-$1M on $100 Trillion Crypto Market

Wall Street veteran Jordi Visser suggested a long-term Bitcoin Price scenario of $600,000 to...

Bitcoin Surges 20% as Dollar Debasement Trade Returns

Bitcoin surged 20% since mid-August, adding roughly $300 billion to its market capitalization in...

Shiba Inu Dips After Brief Rally; Fears of Another Crash

Shiba Inu (SHIB) briefly reclaimed $0.000006 before dipping to $0.000005, signaling renewed weakness.Shibarium’s Total...

Must Read

How Cryptocurrency Works For Beginners?

Welcome to the world of cryptocurrency! If you're new to this exciting and rapidly evolving landscape, you might feel like Alice in Wonderland, exploring...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading