Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
Researchers at Wordfence and Patchstack have disclosed five critical security flaws affecting widely used WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. The most severe issue, tracked as CVE-2026-76581, carries a near-maximum CVSS score of 9.8 and involves an authentication bypass that could allow attackers to gain unauthorized access without valid credentials.
These types of vulnerabilities are particularly dangerous because they can enable full account takeover or remote code execution, giving attackers the ability to control affected websites entirely, insert malicious content, steal customer data, or use compromised sites to launch further attacks. Given the popularity of these plugins and themes across the WordPress ecosystem, a large number of small business websites could be exposed until patches are applied.
For Australian small businesses that rely on WordPress for their website, online store, or booking system, these flaws are a reminder that plugin and theme security is just as important as core WordPress updates. Attackers frequently scan the internet for sites running outdated, vulnerable extensions, making prompt patching essential to avoid becoming an easy target.