Multiple critical security vulnerabilities have been identified across several popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws, carrying CVSS scores as high as 10.0, present significant risks such as unauthenticated remote code execution (RCE), full site takeover, and administrator account hijacking. Security researchers from Wordfence and Patchstack have highlighted that these issues stem from various root causes including authentication bypasses, arbitrary file writes, and sensitive information exposure.
Notably, the GiveWP plugin faces a maximum-severity PHP object injection vulnerability (CVE-2026-82222) that allows attackers to execute arbitrary commands by exploiting a broken serialization sanitizer and a gadget chain in the code. Other significant threats include an authentication bypass in WPMU DEV Dashboard affecting sites using Hub SSO and an arbitrary file write flaw in the Avada theme that enables remote code execution. Website administrators are strongly urged to update the affected plugins and themes to their latest versions immediately to mitigate the risk of complete site compromise.
Top comments (0)