Late this month, security researchers disclosed five separate critical vulnerabilities across popular WordPress plugins and a widely used theme — in the WPMU DEV Dashboard, the Avada theme (paired with Fusion Builder), the TranslatePress translation plugin, the Pods framework, and the GiveWP donation plugin. Several carry the maximum or near-maximum severity score (9.8–10.0 out of 10), and none of them require a username or password to exploit. If a site was running the vulnerable version, an attacker could simply find it and take it over.
I don't usually write about individual CVEs — most are narrow, low-severity, or already patched by the time anyone hears about them. This batch is worth flagging because of the combination: real reach (TranslatePress alone is active on 400,000+ sites, and Avada is one of the best-selling WordPress themes ever), real severity (full admin takeover or remote code execution, not just a glitch), and zero authentication required. Wordfence, the security firm that found and reported two of the five, has already published fixes; the vendors have patched versions out.
Not the specific bug names — those will be forgotten in a month. What's worth taking from this:
This is exactly the kind of thing that's easy to lose track of if you're not checking regularly — which version of which plugin, whether auto-updates are actually on, whether an old theme is still active in the background. If you want a second set of eyes on it, that's a quick thing to check.
Sources: