negativeSYS.SOURCE: The Hacker News• 2026-08-29T21:55:03+05:30
Critical WordPress Plugin and Theme Vulnerabilities Enable Site Takeover and RCE Exploits
Five critical vulnerabilities in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, enable authentication bypass, account takeover, and remote code execution (RCE). These flaws, with CVSS scores up to 10.0, require immediate patching to prevent exploitation.
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution.
The vulnerabilities, according to Wordfence and Patchstack, are listed below -
CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
*** END OF TRANSMISSION ***