CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

August 29, 2026

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Ravie LakshmananAug 29, 2026Vulnerability / Web Security Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below – CVE-2026-76581 (CVSS score: 9.8) – An authentication bypass flaw in the WPMU DEV Dashboard plugin that could allow an unauthenticated attacker, on sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator, to obtain administrator access and achieve site takeover. (Affects all versions up to, and including, 5.0.1) CVE-2026-18431 (CVSS score:…

CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, CVE-2026-58231