Threat Response - Five critical vulnerabilities in WordPress Plugins
Dutch follows English
Security researchers at Wordfence have disclosed five critical vulnerabilities affecting popular WordPress plugins and themes, several of which allow unauthenticated attackers to fully take over affected WordPress websites [1][2][3][4]. Given the severity of these vulnerabilities and the widespread use of the affected components, we strongly recommend updating affected plugins and themes as soon as possible.
Description
Five critical vulnerabilities have been identified in widely used WordPress plugins and themes:
- CVE-2026-76581 [5] (CVSS 9.8): An unauthenticated authentication bypass in the WPMU DEV Dashboard plugin, allowing attackers to gain administrator access [4]. Exploitation requires the site to be connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator account.
- CVE-2026-18431 [6] (CVSS 9.8): An unauthenticated arbitrary file write vulnerability in the Avada theme's Fusion Builder plugin, leading to remote code execution via a complex, six-step exploit chain [3]. Exploitation requires Fusion Builder to be installed and active.
- CVE-2026-19632 [7] (CVSS 9.8): Unauthenticated access to administrator password-reset URLs in TranslatePress, enabling full administrator account takeover [2]. Exploitation requires automatic string saving to be enabled and the target administrator's profile locale set to a published secondary language.
- CVE-2026-19598 [8] (CVSS 9.8): Unauthenticated privilege escalation to Administrator, or password overwrite, in the Pods plugin, resulting in complete site takeover [1]. No special configuration is required.
- CVE-2026-82222 [9] (CVSS 10.0): Unauthenticated PHP object injection in GiveWP, leading to remote code execution. Exploitation requires a published donation form and an active payment gateway.
All five vulnerabilities can be exploited by attackers without any login credentials, and successful exploitation can result in complete compromise of the affected website.
Impact
We estimate the impact of these vulnerabilities as HIGH.
If exploited, attackers can gain complete control over affected WordPress websites. This means they could:
- Steal sensitive customer data, credentials, or business information
- Modify or delete website content
- Install malware or ransomware
- Use your website to attack others
- Damage your organization's reputation
- Cause business disruption and downtime
Risk
We estimate the risk of these vulnerabilities as HIGH, as multiple flaws can be exploited by unauthenticated attackers, with CVE-2026-19598 and CVE-2026-82222 requiring no special or non-default configuration. The affected components are widely deployed: the Avada theme has over 1 million sales [3], TranslatePress is active on roughly 400,000 sites [2], and Pods is active on roughly 100,000 sites [1]. There is currently no evidence of active exploitation, but given the severity and reach of these components, we assess the risk of future exploitation as significant.
Mitigation
Vendors have released security updates that fix these vulnerabilities. Organizations should immediately update the following components if in use:
- WPMU DEV Dashboard: affected versions <= 5.0.1
- Avada theme: affected versions Avada <= 7.16, and Fusion Builder <= 3.16
- TranslatePress: affected versions <= 3.3.1
- Pods: affected versions <= 3.3.9
- GiveWP: affected versions <= 4.16.7.1
No workarounds have been published for these vulnerabilities; patching to the fixed versions is the primary remediation.
What should you do?
You should identify whether any of the affected plugins or themes are installed in your WordPress environment(s) and apply the applicable security updates immediately. Given the number of components involved, we recommend prioritizing a full inventory of installed WordPress plugins and themes across your organization.When in doubt about any entries, please do not hesitate to reach out to our SOC for further assistance.
What will Northwave do?
We will monitor any developments regarding these vulnerabilities. If new critical information about these threats arises, we will reach out to you. You can contact us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1] https://www.wordfence.com/blog/2026/08/100000-wordpress-sites-affected-by-privilege-escalation-vulnerability-in-pods-wordpress-plugin/
[2] https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/
[3] https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/
[4] https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-76581
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-18431
[7] https://nvd.nist.gov/vuln/detail/CVE-2026-19632
[8] https://nvd.nist.gov/vuln/detail/CVE-2026-19598
[9] https://nvd.nist.gov/vuln/detail/CVE-2026-82222
Beveiligingsonderzoekers van Wordfence hebben vijf kritieke kwetsbaarheden bekendgemaakt in populaire WordPress-plugins en -thema's, waarvan meerdere waarbij niet-geauthenticeerde aanvallers volledige controle kunnen krijgen over getroffen WordPress-websites [1][2][3][4]. Gezien de ernst van deze kwetsbaarheden en het grootschalig gebruik van de betrokken componenten, adviseren wij dringend om getroffen plugins en thema's zo snel mogelijk bij te werken.
Beschrijving
Er zijn vijf kritieke kwetsbaarheden vastgesteld in veelgebruikte WordPress-plugins en -thema's:
- CVE-2026-76581 [5] (CVSS 9.8): Een niet-geauthenticeerde authenticatie-bypass in de WPMU DEV Dashboard-plugin, waarmee aanvallers beheerderstoegang kunnen verkrijgen [4]. Uitbuiting vereist dat de site is gekoppeld aan WPMU DEV met Hub Single-Sign On (SSO) ingeschakeld en gekoppeld aan een beheerdersaccount.
- CVE-2026-18431 [6] (CVSS 9.8): Een niet-geauthenticeerde kwetsbaarheid voor het willekeurig schrijven van bestanden in de Fusion Builder-plugin van het Avada-thema, wat via een complexe exploitketen van zes stappen leidt tot remote code execution [3]. Uitbuiting vereist dat Fusion Builder is geïnstalleerd en actief is.
- CVE-2026-19632 [7] (CVSS 9.8): Niet-geauthenticeerde toegang tot URL's voor het resetten van beheerderswachtwoorden in TranslatePress, wat volledige overname van beheerdersaccounts mogelijk maakt [2]. Uitbuiting vereist dat automatisch opslaan van strings is ingeschakeld en dat de profieltaal van de beheerder is ingesteld op een gepubliceerde secundaire taal.
- CVE-2026-19598 [8] (CVSS 9.8): Niet-geauthenticeerde escalatie van rechten naar Administrator, of het overschrijven van wachtwoorden, in de Pods-plugin, wat resulteert in volledige overname van de site [1]. Er is geen speciale configuratie vereist.
- CVE-2026-82222 [9] (CVSS 10.0): Niet-geauthenticeerde PHP-objectinjectie in GiveWP, wat leidt tot remote code execution. Uitbuiting vereist een gepubliceerd donatieformulier en een actieve betalingsgateway.
Deze kwetsbaarheden kunnen door aanvallers worden misbruikt zonder inloggegevens, en succesvolle uitbuiting kan leiden tot volledige compromittering van de getroffen website.
Impact
Wij schatten de impact van deze kwetsbaarheden in als HOOG.
Bij misbruik kunnen aanvallers volledige controle krijgen over getroffen WordPress-websites. Dit betekent dat zij:
- Gevoelige klantgegevens, inloggegevens of bedrijfsinformatie kunnen stelen
- Website-inhoud kunnen wijzigen of verwijderen
- Malware of ransomware kunnen installeren
- Uw website kunnen gebruiken om anderen aan te vallen
- De reputatie van uw organisatie kunnen schaden
- Bedrijfsverstoring en downtime kunnen veroorzaken
Risico
Wij schatten het risico van deze kwetsbaarheden in als HOOG, aangezien meerdere kwetsbaarheden kunnen worden misbruikt door niet-geauthenticeerde aanvallers, waarbij CVE-2026-19598 en CVE-2026-82222 geen speciale of niet-standaard configuratie vereisen. De getroffen componenten zijn wijdverbreid: het Avada-thema is meer dan 1 miljoen keer verkocht [3], TranslatePress is actief op ongeveer 400.000 sites [2], en Pods is actief op ongeveer 100.000 sites [1]. Er is momenteel geen bewijs van actief misbruik, maar gezien de ernst en het bereik van deze componenten schatten wij het risico op toekomstig misbruik als aanzienlijk in.
Mitigatie
Leveranciers hebben beveiligingsupdates uitgebracht die deze kwetsbaarheden verhelpen. Organisaties dienen de volgende componenten, indien in gebruik, onmiddellijk bij te werken:
- WPMU DEV Dashboard: getroffen versies <= 5.0.1
- Avada-thema: getroffen versies Avada <= 7.16, en Fusion Builder <= 3.16
- TranslatePress: getroffen versies <= 3.3.1
- Pods: getroffen versies <= 3.3.9
- GiveWP: getroffen versies <= 4.16.7.1
Er zijn geen workarounds gepubliceerd voor deze kwetsbaarheden; bijwerken naar de gepatchte versies is de primaire remediatie.
Wat moet u doen?
Controleer of de getroffen plugins of thema's in uw WordPress-omgeving(en) zijn geïnstalleerd en de van toepassing zijnde beveiligingsupdates onmiddellijk toe te passen. Gezien het aantal betrokken componenten adviseren wij om prioriteit te geven aan een volledige inventarisatie van geïnstalleerde WordPress-plugins en -thema's binnen uw organisatie.Bij twijfel over bepaalde items kunt u altijd contact opnemen met ons SOC voor verdere ondersteuning.
Wat gaat Northwave doen?
Northwave monitort de ontwikkelingen rondom deze kwetsbaarheden. Mocht er nieuwe belangrijke informatie over deze dreigingen naar voren komen, dan nemen wij contact met u op. U kunt ons telefonisch of per e-mail bereiken voor aanvullende informatie.
Voor aanvullende informatie kunt u ons telefonisch of per e-mail bereiken.E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000
Disclaimer van toepassing, zie onderaan.
Bronnen
[1] https://www.wordfence.com/blog/2026/08/100000-wordpress-sites-affected-by-privilege-escalation-vulnerability-in-pods-wordpress-plugin/
[2] https://www.wordfence.com/blog/2026/08/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-translatepress-wordpress-plugin/
[3] https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/
[4] https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-critical-authentication-bypass-in-wpmu-dev-dashboard-plugin/
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-76581
[6] https://nvd.nist.gov/vuln/detail/CVE-2026-18431
[7] https://nvd.nist.gov/vuln/detail/CVE-2026-19632
[8] https://nvd.nist.gov/vuln/detail/CVE-2026-19598
[9] https://nvd.nist.gov/vuln/detail/CVE-2026-82222

