Technology newsroom
Urgent Alert! 5 Popular WordPress Plugins and Themes Found with Critical Vulnerabilities, Risking Full Website Takeover (RCE) π¨
Critical security vulnerabilities (CVSS 9.8) have been found in 5 popular WordPress plugins and themes, risking website takeover by hackers. System administrators should update immediately.
π Key Takeaways:
- Wordfence and Patchstack have issued a critical security vulnerability warning for 5 popular WordPress plugins and themes.
- The vulnerabilities are extremely severe, with CVSS scores as high as 9.8, potentially allowing hackers to bypass authentication, take over accounts, or execute remote code (RCE).
- Website administrators using WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP must update to the latest versions as soon as possible to mitigate the risks.
Renowned cybersecurity firms Wordfence and Patchstack have released reports detailing the discovery of several critical security vulnerabilities in widely used WordPress plugins and themes. This discovery has raised concerns among website administrators worldwide, as these vulnerabilities could allow malicious actors to gain complete control over websites.
The affected plugins and themes include WPMU DEV Dashboard, the Avada theme (one of the best-selling themes), TranslatePress (a language translation plugin), Pods (a plugin for creating Custom Content Types), and GiveWP (a donation system plugin). Each of these has a large user base, ranging from hundreds of thousands to millions of websites.
π¨ Impact and Severity
The discovered vulnerabilities are diverse and extremely dangerous, ranging from allowing hackers to bypass authentication to log into the system without a password, to account takeover, and ultimately to the most critical vulnerability: Remote Code Execution (RCE). RCE means hackers can execute any commands on the website's server as if they owned the machine itself.
π In-depth Look at CVE-2026-76581
One of the highlighted vulnerabilities is CVE-2026-76581, an Authentication Bypass type vulnerability with a critical CVSS score of 9.8 out of 10. This single vulnerability is sufficient to allow attackers to gain administrator privileges and easily control the website.
π‘οΈ Recommendations for Administrators
For all WordPress website administrators, this is an urgent matter that should not be overlooked. It is recommended to immediately check your website to see if any of the listed plugins or themes are installed. If found, proceed to update to the latest patched versions as quickly as possible. Ignoring this update could lead to severe damage to your data and the organization's reputation.
π¬ Are your websites using these plugins or themes? Have you checked and updated them yet?