474/69 Monday, August 31, 2026

Reports have disclosed Critical vulnerabilities in several WordPress plugins, including WPMU DEV Dashboard, Pods, and GiveWP. The vulnerabilities have CVSS severity scores ranging from 9.8 to 10.0 and could lead to authentication bypass, privilege escalation, user password changes, or command execution on servers, depending on the affected plugin and the configuration of the impacted website.
Reports indicate that CVE-2026-76581 in WPMU DEV Dashboard could allow unauthenticated attackers to gain administrator privileges if the website is connected to WPMU DEV and Hub Single Sign-On is enabled and linked to an administrator account. CVE-2026-19598 in Pods could allow attackers to escalate privileges to administrator level or change user account passwords. CVE-2026-82222 in GiveWP could lead to command execution on the server of websites that have donation forms and payment gateways enabled.
The affected versions reported include WPMU DEV Dashboard version 5.0.1 and earlier, Pods version 3.3.9 and earlier, and GiveWP version 4.16.7.1 and earlier. WordPress administrators should review the plugins in use, update them to fixed versions, and inspect administrator accounts or abnormal activity that may be associated with unauthorized access to the website.
Source: https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
