Close Menu
NCIJ Network NCIJ Network
    What's Hot

    One Nation claims victory on Secret Harbour byelection in Western Australia | Australia news

    August 29, 2026

    3 surveys deliver the same uncomfortable truth about adopting agentic AI

    August 29, 2026

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • One Nation claims victory on Secret Harbour byelection in Western Australia | Australia news
    • 3 surveys deliver the same uncomfortable truth about adopting agentic AI
    • Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
    • UK Police Seize $1.4M in Bitcoin Traced to Shuttered Darknet Markets
    • Your sleep may be hiding an early clue to Alzheimer’s
    • August reveals Australians’ big appetite for weight-loss drugs, love for ‘dupe’ brands and an accelerating EV uptake | Australian economy
    • “We’re not doing 30 bets a year”: Vijay Pande on betting small after running $4 billion at a16z
    • Morning Minute: Solana Jumps with Network Inflation Set to Drop
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 29, 2026Vulnerability / Web Security

    Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution.

    The vulnerabilities, according to Wordfence and Patchstack, are listed below –

    • CVE-2026-76581 (CVSS score: 9.8) – An authentication bypass flaw in the WPMU DEV Dashboard plugin that could allow an unauthenticated attacker, on sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator, to obtain administrator access and achieve site takeover. (Affects all versions up to, and including, 5.0.1)
    • CVE-2026-18431 (CVSS score: 9.8) – An arbitrary file write flaw in the Avada theme for WordPress that makes it possible for an unauthenticated attacker to write attacker-controlled files to the server, which, in turn, can be exploited to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. (Affects all versions up to, and including, 7.16, when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16)
    • CVE-2026-19632 (CVSS score: 9.8) – A sensitive information exposure flaw in the “TranslatePress – Translate Multilingual sites with AI Translation” plugin that could allow an unauthenticated attacker to extract the raw administrator password-reset URL, including the plaintext reset key and login parameters, and enable full administrator account takeover. (Affects all versions up to, and including, 3.3.1 only when automatic string saving is enabled and the target administrator’s profile locale is set to a published secondary language)
    • CVE-2026-19598 (CVSS score: 9.8) – A privilege escalation flaw in the “Pods – Custom Content Types and Fields” plugin that allows an unauthenticated attacker to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner’s, resulting in complete site takeover. (Affects all versions up to, and including, 3.3.9)
    • CVE-2026-82222 (CVSS score: 10.0) – A vulnerability in the GiveWP plugin that allows an attacker to execute arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway. (Affects all versions up to, and including, 4.16.7.1)
    Cybersecurity

    “The flaw chains a broken ‘safe unserialize’ helper, a donation flow that feeds that helper attacker-controlled data, and a gadget chain in code that GiveWP ships,” Patchstack said about CVE-2026-82222. “This case shows how PHP object injection turns into remote code execution when three ingredients line up: a place to store an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded classes.”

    “The root causes are common: trusting a serialization sanitizer that does not actually strip objects, unserializing data read back from the database as if it were trusted, and shipping development-only libraries into production where they provide ready-made gadget chains.”

    critical enable flaws Plugin RCE site takeover theme WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Brave browser adds email aliases to help users evade tracking

    PaperCut Releases Emergency Patch for Exploited Zero-Day

    Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

    Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

    OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

    ATF Confirms Cyber Incident After Ransomware Group Claims Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    One Nation claims victory on Secret Harbour byelection in Western Australia | Australia news

    August 29, 2026

    3 surveys deliver the same uncomfortable truth about adopting agentic AI

    August 29, 2026

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    August 29, 2026

    UK Police Seize $1.4M in Bitcoin Traced to Shuttered Darknet Markets

    August 29, 2026
    Latest Posts

    Chart of the Week: Outside groups spend millions on House primaries • OpenSecrets

    July 30, 2026

    NASA Webb Explores Family Tree of Newly Discovered Distant Objects

    July 30, 2026

    There’s a New Way to Protect Bitcoin From Future Quantum Attacks, Researchers Say

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    One Nation claims victory on Secret Harbour byelection in Western Australia | Australia news

    August 29, 2026

    3 surveys deliver the same uncomfortable truth about adopting agentic AI

    August 29, 2026

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.