Critical WordPress plugin and theme flaws let unauthenticated attackers seize sites
Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.
- Check
- Inventory your WordPress sites for the WPMU DEV Dashboard, Avada, Pods, and TranslatePress components, and update each to its patched version now, prioritizing internet-facing and multi-author sites.
- Affected
- Sites running vulnerable versions of WPMU DEV Dashboard, Avada, Pods, or TranslatePress (CVE-2026-76581, CVE-2026-18431, CVE-2026-19598, CVE-2026-19632); unauthenticated attackers can gain admin access, reset passwords, or execute code.
- Fix
- Patch every affected plugin and theme, audit for unexpected admin accounts, changed passwords, and new PHP files, front sites with a web application firewall, and rotate credentials on any exposed site.