August 30, 2026
wordpress-themes.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

Ravie LakshmananAug 29, 2026Vulnerability / Net Safety

A number of important safety flaws have been disclosed in WordPress plugins and themes, together with WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that would result in authentication bypass, account takeover, and arbitrary code execution.

The vulnerabilities, in keeping with Wordfence and Patchstack, are listed beneath –

  • CVE-2026-76581 (CVSS rating: 9.8) – An authentication bypass flaw within the WPMU DEV Dashboard plugin that would enable an unauthenticated attacker, on websites related to WPMU DEV with Hub Single-Signal On (SSO) enabled and mapped to an administrator, to acquire administrator entry and obtain web site takeover. (Impacts all variations as much as, and together with, 5.0.1)
  • CVE-2026-18431 (CVSS rating: 9.8) – An arbitrary file write flaw within the Avada theme for WordPress that makes it attainable for an unauthenticated attacker to write down attacker-controlled information to the server, which, in flip, may be exploited to create and execute arbitrary PHP information, leading to distant code execution and full web site compromise. (Impacts all variations as much as, and together with, 7.16, when the Fusion Builder plugin is put in and lively in variations as much as, and together with, 3.16)
  • CVE-2026-19632 (CVSS rating: 9.8) – A delicate info publicity flaw within the “TranslatePress – Translate Multilingual websites with AI Translation” plugin that would enable an unauthenticated attacker to extract the uncooked administrator password-reset URL, together with the plaintext reset key and login parameters, and allow full administrator account takeover. (Impacts all variations as much as, and together with, 3.3.1 solely when computerized string saving is enabled and the goal administrator’s profile locale is ready to a broadcast secondary language)
  • CVE-2026-19598 (CVSS rating: 9.8) – A privilege escalation flaw within the “Pods – Customized Content material Sorts and Fields” plugin that enables an unauthenticated attacker to escalate their privileges to Administrator or overwrite the password of any consumer account, together with the location proprietor’s, leading to full web site takeover. (Impacts all variations as much as, and together with, 3.3.9)
  • CVE-2026-82222 (CVSS rating: 10.0) – A vulnerability within the GiveWP plugin that enables an attacker to execute arbitrary instructions on the server of a GiveWP web site that has one revealed donation kind and one lively fee gateway. (Impacts all variations as much as, and together with, 4.16.7.1)

“The flaw chains a damaged ‘secure unserialize’ helper, a donation stream that feeds that helper attacker-controlled information, and a gadget chain in code that GiveWP ships,” Patchstack stated about CVE-2026-82222. “This case exhibits how PHP object injection turns into distant code execution when three components line up: a spot to retailer an attacker-controlled serialized object, code that later unserializes it, and a gadget chain in loaded lessons.”

“The basis causes are widespread: trusting a serialization sanitizer that doesn’t truly strip objects, unserializing information learn again from the database as if it have been trusted, and delivery development-only libraries into manufacturing the place they supply ready-made gadget chains.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *