# Five critical WordPress flaws expose sites to takeover or code execution

_Saturday, August 29, 2026 at 12:25 PM EDT · Security · Latest · Tier 2 — Notable_

![Five critical WordPress flaws expose sites to takeover or code execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiROOqCRPV4u9cWfJL8nvCYKi4Ake-ki3_uh8Qn8RJ0P20h3Mz_qxVfF856pJ9DQZMHy922CeLwOHDc37Gpb4p1UCTMx6cMT5HeeAP_w4RitCuQficYcGDDkqpDVfW_nA3M7qWT-WyM6A5Adk3J2e8kMWSG1GSUOatrcVBmc7fmb2-ovadVS3fOdkd1ubFx/s1700-e365/wordpress-themes.jpg)

Multiple critical flaws disclosed in WordPress plugins and themes could allow unauthenticated attackers to take over administrator accounts or execute code on affected servers. The affected products include WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. The source lists CVSS scores of 9.8 for four issues and 10.0 for the GiveWP vulnerability, with attack conditions varying by product configuration. The disclosures identify affected versions but do not state whether fixes are available or whether the flaws are being exploited.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html)

---
Canonical: https://techandbusiness.org/newswire/6fXQkBiIjCTSjpQaBDkoQC
Retrieved: 2026-08-29T20:56:54.288Z
Publisher: Tech & Business (techandbusiness.org)
