Back to advisories

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Critical vulnerabilities (CVSS 10.0) discovered in five major WordPress plugins/themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Unauthenticated attackers can bypass authentication, hijack accounts, execute arbitrary code, and fully compromise affected sites. Any organization running WordPress with these plugins/themes is at immediate risk.

CRITICALAdvisoryAug 30, 2026
Action required
Audit all WordPress instances for WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP installations. Update to patched versions immediately. If updates unavailable, disable plugins/themes until patches release. Scan web logs for exploitation attempts targeting these components.
Affected products
WPMU DEV DashboardAvadaTranslatePressPodsGiveWP