Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [incident, wordpress, plugin, theme, rce, auth-bypass, site-takeover] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Wordfence and Patchstack disclosed five critical flaws on 29 August 2026 in widely deployed WordPress plugins and themes: WPMU DEV Dashboard (CVE-2026-76581, CVSS 9.8 โ€” authentication bypass to administrator takeover via Hub single sign-on), the Avada theme (CVE-2026-18431, CVSS 9.8 โ€” arbitrary file write enabling remote code execution when Fusion Builder is active), and TranslatePress (CVE-2026-19632, CVSS 9.8 โ€” exposure of raw administrator password-reset URLs to unauthenticated attackers), plus flaws in Pods and the GiveWP donation plugin, the latter allowing server-side command execution.

Combined, the bundle covers authentication bypass, account takeover and arbitrary code execution across millions of WordPress sites. No in-the-wild exploitation had been disclosed at publication, but GiveWP's flaw arrived with a working command-execution path, and the plugin ecosystem is the core SMB attack surface โ€” a material consideration for Australian small businesses and agencies running WordPress estates.

Source