Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Security Alert: Five Critical WordPress Plugin and Theme Flaws Expose Sites to Authentication Bypass, Account Takeover, and Remote Code Execution




Five critical security flaws have been discovered in popular WordPress plugins and themes, exposing sites to authentication bypass, account takeover, and remote code execution. In this article, we will delve into the details of these critical vulnerabilities and provide guidance on how to mitigate the risks associated with them. The vulnerabilities, which have been disclosed by reputable security firms Wordfence and Patchstack, are listed in the table below:

| Vulnerability | Description | Affected Versions | CVSS Score |
| --- | --- | --- | --- |
| CVE-2026-76581 | Authentication bypass flaw in WPMU DEV Dashboard plugin | All versions up to 5.0.1 | 9.8 |
| CVE-2026-18431 | File write flaw in Avada theme | All versions up to 7.16 | 9.8 |
| CVE-2026-19632 | Sensitive information exposure flaw in TranslatePress plugin | All versions up to 3.3.1 | 9.8 |
| CVE-2026-19598 | Privilege escalation flaw in Pods plugin | All versions up to 3.3.9 | 9.8 |
| CVE-2026-82222 | Vulnerability in GiveWP plugin | All versions up to 4.16.7.1 | 10.0 |

It is essential to update your plugins and themes to the latest versions to mitigate the risks associated with these vulnerabilities. Stay tuned for further updates and guidance on how to protect your WordPress sites from these critical security flaws.

  • Five critical security flaws have been discovered in popular WordPress plugins and themes, posing a significant risk to site owners and administrators.
  • The vulnerabilities allow authentication bypass, account takeover, and remote code execution, and affect plugins and themes used by over 5 million WordPress sites.
  • WPMU DEV Dashboard plugin, Avada theme, TranslatePress plugin, Pods plugin, and GiveWP plugin are among those affected by the vulnerabilities.
  • Updating plugins and themes to the latest versions is highly recommended to mitigate the risks associated with these vulnerabilities.
  • Additional measures to protect sites include enabling two-factor authentication, using a reputable security plugin, regularly backing up the site, using strong passwords, and keeping WordPress core and plugins up to date.



  • The WordPress community has been dealt a significant blow with the recent discovery of five critical security flaws in popular plugins and themes. The vulnerabilities, which have been disclosed by reputable security firms Wordfence and Patchstack, pose a significant risk to site owners and administrators, who may be exposed to authentication bypass, account takeover, and remote code execution. In this article, we will delve into the details of these critical vulnerabilities and provide guidance on how to mitigate the risks associated with them.

    The first vulnerability, CVE-2026-76581, affects the WPMU DEV Dashboard plugin, which is used by over 5 million WordPress sites. This flaw allows an unauthenticated attacker to bypass authentication and gain administrator access to sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator. The vulnerability is present in all versions up to and including 5.0.1, making it a high-priority fix for affected sites.

    The second vulnerability, CVE-2026-18431, is a file write flaw in the Avada theme for WordPress. This vulnerability allows an unauthenticated attacker to write attacker-controlled files to the server, which can be exploited to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. The vulnerability affects all versions up to and including 7.16, when the Fusion Builder plugin is installed and active in versions up to and including 3.16.

    The third vulnerability, CVE-2026-19632, is a sensitive information exposure flaw in the "TranslatePress – Translate Multilingual sites with AI Translation" plugin. This vulnerability allows an unauthenticated attacker to extract the raw administrator password-reset URL, including the plaintext reset key and login parameters, and enable full administrator account takeover. The vulnerability affects all versions up to and including 3.3.1 only when automatic string saving is enabled and the target administrator's profile locale is set to a published secondary language.

    The fourth vulnerability, CVE-2026-19598, is a privilege escalation flaw in the "Pods – Custom Content Types and Fields" plugin. This vulnerability allows an unauthenticated attacker to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, resulting in complete site takeover. The vulnerability affects all versions up to and including 3.3.9.

    The fifth and most critical vulnerability, CVE-2026-82222, is a vulnerability in the GiveWP plugin that allows an attacker to execute arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway. The vulnerability affects all versions up to and including 4.16.7.1 and has a CVSS score of 10.0, making it a high-priority fix for affected sites.

    These critical vulnerabilities highlight the importance of keeping your WordPress plugins and themes up to date. It is recommended that site owners and administrators take the following steps to mitigate the risks associated with these vulnerabilities:

    1. Update your WPMU DEV Dashboard plugin to version 5.0.2 or higher.
    2. Update your Avada theme to version 7.17 or higher.
    3. Update your TranslatePress plugin to version 3.3.2 or higher.
    4. Update your Pods plugin to version 3.3.10 or higher.
    5. Update your GiveWP plugin to version 4.16.8.1 or higher.

    In addition to updating your plugins and themes, it is also recommended that site owners and administrators take the following steps to protect their sites from these vulnerabilities:

    1. Enable two-factor authentication (2FA) on your WordPress site.
    2. Use a reputable security plugin, such as Wordfence, to monitor your site for malware and vulnerabilities.
    3. Regularly backup your site's database and files to prevent data loss in the event of a vulnerability being exploited.
    4. Use a strong and unique password for your site's administrator account.
    5. Keep your WordPress core and plugins up to date, as new vulnerabilities are often patched in these updates.

    By following these steps, site owners and administrators can help protect their sites from the risks associated with these critical vulnerabilities and ensure that their sites remain secure and reliable.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Security-Alert-Five-Critical-WordPress-Plugin-and-Theme-Flaws-Expose-Sites-to-Authentication-Bypass-Account-Takeover-and-Remote-Code-Execution-ehn.shtml

  • https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html


  • Published: Sat Aug 29 16:51:12 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us