← All articles

Critical WordPress plugin and theme flaws let unauthenticated attackers seize sites

Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.

Check
Inventory your WordPress sites for the WPMU DEV Dashboard, Avada, Pods, and TranslatePress components, and update each to its patched version now, prioritizing internet-facing and multi-author sites.
Affected
Sites running vulnerable versions of WPMU DEV Dashboard, Avada, Pods, or TranslatePress (CVE-2026-76581, CVE-2026-18431, CVE-2026-19598, CVE-2026-19632); unauthenticated attackers can gain admin access, reset passwords, or execute code.
Fix
Patch every affected plugin and theme, audit for unexpected admin accounts, changed passwords, and new PHP files, front sites with a web application firewall, and rotate credentials on any exposed site.