Wednesday , September 23 2026
WordPress

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These issues could let hackers bypass login, take over accounts, and run any code.

The vulnerabilities, according to Wordfence and Patchstack, are listed below:

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

CVE-2026-76581 (CVSS score: 9.8): An authentication problem in the WPMU DEV Dashboard plugin might let an attacker without an account get into websites linked to WPMU DEV with Hub Single-Sign On (SSO) turned on and connected to an admin. This could let them gain admin access and take over the site. (Affects all versions up to and including 5.0.1)

CVE-2026-18431 (CVSS score: 9.8): An arbitrary file write issue in the Avada theme for WordPress lets a hacker without access write their own files to the server. This can be used to make and run unsafe PHP files, leading to remote code execution and full site takeover. (Affects all versions up to and including 7.16, when the Fusion Builder plugin is active in versions up to and including 3.16)

CVE-2026-19632 (CVSS score: 9.8): A flaw in the “TranslatePress – Translate Multilingual sites with AI Translation” plugin can let a hacker without an account get the main password-reset link. This includes the plain reset key and login details, which can let the hacker take over the admin account. (This affects all versions up to 3.3.1 only when automatic string saving is on and the admin’s profile language is a published secondary language)

CVE-2026-19598 (CVSS score: 9.8): The flaw in the “Pods – Custom Content Types and Fields” plugin lets an attacker without an account gain Administrator rights or change any user’s password, even the owner’s, leading to a full site takeover. (Affects all versions up to, and including, 3.3.9)

CVE-2026-82222 (CVSS score: 10.0): A flaw in the GiveWP plugin lets a hacker run any commands on the server of a GiveWP site with one published donation form and one active payment option. (Affects all versions up to, and including, 4.16.7.1)

“The flaw chains a broken ‘safe unserialize’ helper, a donation flow that feeds that helper attacker-controlled data, and a gadget chain in code that GiveWP ships,” Patchstack said about CVE-2026-82222. “This case shows how PHP object injection turns into remote code execution when three ingredients line up: a place to store an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded classes.”

“The root causes are common: trusting a serialization sanitizer that does not actually strip objects, unserializing data read back from the database as if it were trusted, and shipping development-only libraries into production where they provide ready-made gadget chains.”

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …