
Critical Security Flaws Disclosed in Popular WordPress Plugins and Themes
WordPressSecurityFlawsAuthenticationBypassCodeExecution
Multiple critical security flaws were disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These vulnerabilities could lead to authentication bypass, account takeover, and arbitrary code execution. One identified flaw is CVE-2026-76581 with a CVSS score of 9.8, described as an authentication bypass issue. The findings were reported by Wordfence and Patchstack.