Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Executive Summary
WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—contain critical flaws that enable authentication bypass, account takeover, and arbitrary code execution. The most severe, CVE‑2026‑76581, scores 9.8 on CVSS. These vulnerabilities allow attackers to take full control of affected sites.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-29T16:25:03+00:00 - Category: threat-intel
Original Description: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
"The highest stage in moral ure at which we can arrive is when we recognize that we ought to control our thoughts."
— Charles Darwin