Five critical vulnerabilities discovered across popular WordPress plugins and themes expose millions of websites to remote code execution and account takeover attacks. Security researchers at Wordfence and Patchstack disclosed flaws in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP that attackers can exploit without authentication.

CVE-2026-76581 carries a CVSS score of 9.8, indicating a near-maximum severity rating. This authentication bypass flaw creates a direct pathway for attackers to circumvent login protections and gain unauthorized administrative access to WordPress installations. The vulnerability's high score reflects the ease of exploitation and broad impact across affected sites.

WordPress powers approximately 43% of all websites globally, making the platform a high-value target for attackers. These five plugins and themes collectively serve millions of installations, ranging from small business websites to enterprise deployments. Each vulnerability presents distinct attack vectors but converges on a single outcome: complete site compromise.

WPMU DEV Dashboard manages site analytics, backups, and security for WordPress networks. An authentication bypass in this plugin grants attackers immediate access to sensitive administrative functions without needing valid credentials. The WPMU DEV platform serves approximately 1 million websites, meaning exposure reaches a substantial portion of the WordPress ecosystem.

Avada ranks among the most popular WordPress themes, powering over 700,000 websites. Vulnerabilities in themes carry particular risk because themes apply across all content and posts on a site. Attackers exploiting theme flaws gain access to shared resources and can inject malicious code that affects every page.

TranslatePress handles multilingual site functionality for hundreds of thousands of WordPress installations. A flaw in translation plugins provides attackers a vector to inject malicious code while maintaining invisibility from language-specific content management. GiveWP powers donation processing for nonprofits and charities, meaning vulnerabilities directly threaten financial transactions and donor data.

Pods, a custom content type builder used by over 100,000 sites, extends WordPress core functionality. Plugin flaws in content management tools expose the underlying database structure and administrative controls.

Organizations running affected plugins and themes face immediate risk. Attackers exploit authentication bypass flaws within hours of public disclosure. Remote code execution vulnerabilities enable attackers to install backdoors, steal databases, inject ransomware, or pivot to connected systems. Account takeover attacks result in permanent loss of administrative control over WordPress installations.

The vulnerabilities affect both current and outdated plugin versions. WordPress administrators running automatic updates receive patches quickly, but many organizations delay updates or run older versions. Legacy WordPress installations present the highest risk due to delayed patch deployment and limited security monitoring.

Wordfence and Patchstack recommend immediate action: update all affected plugins and themes to patched versions, audit administrative account access logs for suspicious login activity, and implement Web Application Firewall rules to block exploitation attempts. Organizations should also reset administrative passwords and review user permissions to remove unauthorized accounts.

The concurrent disclosure of multiple critical flaws across different plugins and themes reflects an active research cycle targeting WordPress infrastructure. Attackers maintain exploit code for authentication bypass and RCE vulnerabilities for weeks after publication, making timely patching essential for defensive operations.