Patch rush for five WordPress add-ons after takeover-grade flaws

Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.

CSBadmin
2 Min Read

Wordfence and Patchstack have disclosed five critical flaws in popular WordPress plugins and themes that can lead to authentication bypass, account takeover, and remote code execution.

Sites running the WPMU DEV Dashboard plugin with Hub single sign-on face CVE-2026-76581 (CVSS 9.8). The authentication bypass lets a remote attacker claim an administrator’s privileges and seize the whole site. Every version through 5.0.1 is exposed.

The Avada theme carries CVE-2026-18431 (9.8), an arbitrary file write flaw that lets an unauthenticated attacker plant PHP files on the server for remote code execution when the Fusion Builder plugin is active. Versions through 7.16, with Fusion Builder through 3.16, are vulnerable.

CVE-2026-19632 (9.8) in TranslatePress exposes the raw administrator password-reset URL, including the plaintext reset key, allowing account takeover. It affects versions through 3.3.1 when automatic string saving is enabled and the admin’s profile locale is a published secondary language.

Pods, a custom content framework plugin, exposes CVE-2026-19598 (9.8) in versions through 3.3.9. The privilege escalation bug allows unauthenticated users to reach administrator status or rewrite any account password, including the site owner’s.

The highest-rated issue is CVE-2026-82222 (CVSS 10.0) in GiveWP, a donation plugin: a broken safe unserialize helper, attacker-controlled data, and a gadget chain combine into PHP object injection that executes arbitrary commands on the server. Versions through 4.16.7.1 are affected.

Patchstack said the root causes are common across plugins: trusting a serialization sanitizer that does not strip objects and shipping development-only libraries into production. Site owners should update all five components immediately.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.