- Five critical vulnerabilities in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, could allow attackers to take over sites completely.
- Two of the flaws, CVE-2026-76581 in WPMU DEV Dashboard and CVE-2026-18431 in Avada, score 9.8 on the CVSS scale and enable authentication bypass and remote code execution without any prior access.
- The most severe vulnerability, CVE-2026-82222 in GiveWP, carries a perfect 10.0 CVSS score and exploits a broken unserialize function to achieve command execution on the server.
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below.
A critical authentication bypass flaw in the WPMU DEV Dashboard plugin, tracked as CVE-2026-76581, allows an unauthenticated attacker to obtain administrator access and achieve site takeover. This affects all plugin versions up to and including 5.0.1 when Hub Single-Sign On is enabled and mapped to an administrator.
Meanwhile, a remote code execution vulnerability in the Avada theme, CVE-2026-18431, enables an unauthenticated attacker to write malicious files and execute arbitrary PHP code. The flaw impacts Avada versions up to 7.16 when the Fusion Builder plugin is active in versions up to 3.16.
Another critical issue, CVE-2026-19632 in the TranslatePress plugin, exposes raw administrator password-reset URLs, enabling full account takeover. This affects plugin versions up to 3.3.1 only when automatic string saving is enabled and the target administrator’s locale is set to a published secondary language.
A privilege escalation flaw in the Pods plugin, CVE-2026-19598, allows an unauthenticated attacker to gain administrator privileges or overwrite any user password. The vulnerability affects all Pods versions up to and including 3.3.9.
The most severe vulnerability, CVE-2026-82222 in the GiveWP plugin, carries a CVSS score of 10.0 and enables arbitrary command execution. Patchstack explained that the flaw chains a broken safe unserialize helper, a donation flow feeding attacker-controlled data, and a gadget chain in code that GiveWP ships. “This case shows how PHP object injection turns into remote code execution when three ingredients line up: a place to store an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded classes.” The vulnerability affects GiveWP versions up to 4.16.7.1.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
