CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5362

As cited

Copy frozen at (site build).

vulnerabilities

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical vulnerabilities were disclosed across five WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws enable attackers to bypass authentication, takeover accounts, and execute arbitrary code on affected sites. CVE-2026-76581 carries a CVSS score of 9.8.

Why it matters: WordPress site administrators running these plugins or themes face immediate risk of account compromise and complete site takeover; patching these flaws should be prioritized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical vulnerabilities have been disclosed across five widely-used WordPress plugins and themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. CVE-2026-76581, with a CVSS score of 9.8, represents an authentication bypass flaw that could lead to account takeover or remote code execution (RCE). These flaws pose significant risks to WordPress site owners and administrators relying on these components.

Why it matters: WordPress site administrators and security teams using these plugins and themes need to prioritize patching to prevent unauthorized access, account compromise, and potential site takeover.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical vulnerabilities have been disclosed across five widely-used WordPress plugins and themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. CVE-2026-76581, with a CVSS score of 9.8, represents an authentication bypass flaw that could lead to account takeover or remote code execution (RCE). These flaws pose significant risks to WordPress site owners and administrators relying on these components.

Why it matters: WordPress site administrators and security teams using these plugins and themes need to prioritize patching to prevent unauthorized access, account compromise, and potential site takeover.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary