Critical WordPress Flaws Put Websites at Risk
Security researchers have disclosed five critical vulnerabilities in popular WordPress plugins and themes. The flaws could allow attackers to take over websites, gain administrator access, or execute malicious code on servers.
The affected products include WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP.
- WPMU DEV Dashboard – CVE-2026-76581 (9.8): An authentication bypass could allow an unauthenticated attacker to gain administrator access and take over a website when Hub SSO is enabled.
- Avada – CVE-2026-18431 (9.8): An arbitrary file write vulnerability could allow attackers to upload malicious PHP files and execute code on the server.
- TranslatePress – CVE-2026-19632 (9.8): Attackers could obtain sensitive password-reset information and potentially take control of administrator accounts under specific configuration conditions.
- Pods – CVE-2026-19598 (9.8): An unauthenticated attacker could escalate privileges to Administrator or change another user's password, including the site owner's.
- GiveWP – CVE-2026-82222 (10.0): A PHP object injection flaw could allow attackers to execute arbitrary commands on vulnerable servers when certain donation and payment configurations are present.
Website administrators should update all affected plugins and themes to their latest patched versions and review their WordPress accounts and server activity for signs of compromise.