Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security vulnerabilities in WordPress plugins and themes have been disclosed, enabling authentication bypass, account takeover, and remote code execution.

Through the Reader lens — Multiple critical security vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, ThemeFusion Avada, TranslatePress, Pods, GiveWP, Super Forms, and Elementor Pro. These flaws enable authentication bypass, account takeover, and remote code execution, with CVSS scores reaching 10.0. Threat actors are already actively exploiting these vulnerabilities in the wild, particularly targeting Super Forms and Elementor Pro installations. Public proof-of-concept code is available, lowering the barrier for attackers. The affected plugins span a wide range of functionality from form builders to translation tools and donation platforms, meaning millions of WordPress sites could be at risk. No patches are currently available for all affected products, forcing administrators to consider temporary mitigation measures. Security teams should immediately audit their WordPress installations and implement compensating controls while waiting for vendor fixes.
What to watch next
- Audit WordPress plugin inventory for affected versions
- Monitor for suspicious authentication and file upload activity
- Implement web application firewall rules to block known exploit patterns
- Track vendor security advisories for patch releases
