HackerFeeds

CyberSecurity News

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News
· August 29, 2026

AI summary

Multiple critical security flaws have been found in several WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These vulnerabilities could allow attackers to bypass authentication, take over accounts, or execute arbitrary code. One of the flaws, identified as CVE-2026-76581, is an authentication bypass issue with a high CVSS score of 9.8. This vulnerability and others like it could have severe consequences, including site takeover and remote code execution. The flaws were disclosed by Wordfence and Patchstack, highlighting the need for users to address these security issues. The affected plugins and themes are widely used, making the vulnerabilities a significant concern for WordPress site owners.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/08/five-critical-wordpress-plugin-and.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.