Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Wordfence and Patchstack disclosed five critical flaws on 29 August 2026 in widely deployed WordPress plugins and themes: WPMU DEV Dashboard (CVE-2026-76581, CVSS 9.8 โ authentication bypass to administrator takeover via Hub single sign-on), the Avada theme (CVE-2026-18431, CVSS 9.8 โ arbitrary file write enabling remote code execution when Fusion Builder is active), and TranslatePress (CVE-2026-19632, CVSS 9.8 โ exposure of raw administrator password-reset URLs to unauthenticated attackers), plus flaws in Pods and the GiveWP donation plugin, the latter allowing server-side command execution.
Combined, the bundle covers authentication bypass, account takeover and arbitrary code execution across millions of WordPress sites. No in-the-wild exploitation had been disclosed at publication, but GiveWP's flaw arrived with a working command-execution path, and the plugin ecosystem is the core SMB attack surface โ a material consideration for Australian small businesses and agencies running WordPress estates.