Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical flaws in WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP can enable authentication bypass, administrator account takeover, arbitrary file write, and remote code execution. Patchstack and Wordfence say the GiveWP issue chains unsafe unserialization with attacker-controlled data and a gadget chain to achieve command execution. #WPMUDEVDashboard #Avada #TranslatePress #Pods #GiveWP #CVE202676581 #CVE202618431 #CVE202619632 #CVE202619598 #CVE202682222

Keypoints

  • WPMU DEV Dashboard has an authentication bypass that can lead to administrator access.
  • Avada contains an arbitrary file write flaw that can result in remote code execution.
  • TranslatePress may expose password reset URLs and enable full administrator takeover.
  • Pods allows privilege escalation or password overwrites for any user account.
  • GiveWP is vulnerable to arbitrary command execution through a chained PHP object injection issue.

Read More: https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html