criticalZero-Day

Critical WordPress Plugin and Theme Vulnerabilities Enabling Site Takeover and RCE

First seen Aug 30, 2026 · Updated Aug 30, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityauthentication-bypassrceaccount-takeovercms-security

Five critical vulnerabilities have been disclosed across popular WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—that can lead to authentication bypass, account takeover, and remote code execution. The most severe flaw, CVE-2026-76581, carries a CVSS score of 9.8 and allows attackers to bypass authentication controls entirely. These issues pose significant risk to any organization running affected WordPress installations, as exploitation could lead to full site compromise.

Technical Analysis

CVE-2026-76581 (CVSS 9.8) is an authentication bypass vulnerability, reportedly in the WPMU DEV Dashboard plugin, that could allow unauthenticated attackers to gain administrative access to WordPress sites. Additional flaws disclosed by Wordfence and Patchstack affect Avada theme, TranslatePress, Pods, and GiveWP plugins, spanning issues that enable account takeover and arbitrary code execution, likely through improper capability checks, insecure REST API endpoints, or unsanitized input leading to PHP object injection or file upload bypasses. Exploitation typically requires no more than crafted HTTP requests to vulnerable endpoints, making mass exploitation via automated scanning feasible once PoCs circulate. Organizations using WordPress as a front-end or content backend for AI agent-driven chatbots, RAG pipelines that scrape or ingest site content, or automation workflows that interact with WordPress via REST API/webhooks should treat any compromised install as a potential source of poisoned data or a pivot point for credential theft affecting connected agent tooling.

Affected Systems

WPMU DEV Dashboard plugin (version prior to patched release), Avada theme (Fusion Builder), TranslatePress plugin, Pods plugin, GiveWP plugin — specific vulnerable version ranges to be confirmed via Wordfence/Patchstack advisories; all self-hosted WordPress sites running unpatched versions of these components

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published at time of disclosure; monitor Wordfence and Patchstack advisories for exploitation indicators

Remediation Steps

  1. 1

    Patch affected plugins/themes immediately

    Update WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP to the latest patched versions as specified in Wordfence and Patchstack advisories.

  2. 2

    Audit user accounts and admin access

    Review WordPress admin and user accounts for unauthorized additions or privilege escalations that may indicate prior exploitation.

  3. 3

    Enable WAF rules

    Deploy or update Web Application Firewall rules (e.g., Wordfence firewall) to block known exploitation patterns for these CVEs.

  4. 4

    Rotate credentials and API keys

    Rotate WordPress admin passwords, API keys, and any secrets exposed to or stored on the affected site, especially if used by connected automation or AI agent integrations.

  5. 5

    Monitor logs for indicators of compromise

    Review server and plugin logs for anomalous authentication attempts, unexpected file changes, or unauthorized REST API calls.

CVE / Advisory IDs

CVE-2026-76581

Industries Most Exposed

mediae-commercenonprofittechnologymarketinggeneral web hosting

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.