← Back to feed
vulnerabilities⚠ Single-originCVSS 10.0 criticalCVE-2026-76581CVE-2026-18431CVE-2026-196322 sources · 6d ago

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security vulnerabilities in WordPress plugins and themes have been disclosed, enabling authentication bypass, account takeover, and remote code execution.

AffectedUnited States Avada Elementor Pro GiveWP Pods Super Forms TranslatePress Wordpress WPMU DEV Dashboard Patchstack Wordfence
2 outlets · 1 origin · Single-origin
India × 2

Through the Reader lens — Multiple critical security vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, ThemeFusion Avada, TranslatePress, Pods, GiveWP, Super Forms, and Elementor Pro. These flaws enable authentication bypass, account takeover, and remote code execution, with CVSS scores reaching 10.0. Threat actors are already actively exploiting these vulnerabilities in the wild, particularly targeting Super Forms and Elementor Pro installations. Public proof-of-concept code is available, lowering the barrier for attackers. The affected plugins span a wide range of functionality from form builders to translation tools and donation platforms, meaning millions of WordPress sites could be at risk. No patches are currently available for all affected products, forcing administrators to consider temporary mitigation measures. Security teams should immediately audit their WordPress installations and implement compensating controls while waiting for vendor fixes.

What to watch next

  • Audit WordPress plugin inventory for affected versions
  • Monitor for suspicious authentication and file upload activity
  • Implement web application firewall rules to block known exploit patterns
  • Track vendor security advisories for patch releases

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

The Hacker News / Security ResearchersIndiaCritical disclosure of vulnerabilities and active exploitation

Security researchers and The Hacker News report that multiple critical vulnerabilities in WordPress plugins and themes enable authentication bypass, account takeover, and remote code execution. Threat actors are actively exploiting these flaws, particularly in Super Forms and Elementor Pro, with public proof-of-concept code available.

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • WordPress plugin/theme users (WPMU DEV Dashboard, ThemeFusion Avada, TranslatePress, Pods, GiveWP, Super Forms, Elementor Pro) remote code execution · immediate
  • Organizations running WordPress sites authentication bypass · immediate
  • Web application security teams patch required · days

Sources (2)

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE — Prism