WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 7–12 of 44 records · Updated September 29, 2026

Medium
CVE-2026-92212

JetFormBuilder

CVSS6.1

BitFire's FREE WAF blocks the malicious query-string payloads behind the JetFormBuilder CVE-2026-92212 reflected XSS before WordPress processes the request.

Affected sites
80000
Attack class
Reflected Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-89426

Knit Pay

CVSS8.8

CVE-2026-89426 lets any Knit Pay 9.6.1.0 user become administrator via Gravity Forms. BitFire FREE Bot Protection and PRO RASP stop the chain.

Affected sites
2000
Attack class
Broken Access Control
BitFire protectionSecure with BitFire PRO RASP + BitFire Bot Protection
Read technical analysis
High
CVE-2026-84281

Fancy Product Designer

CVSS7.2

BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX delivery and script payload behind CVE-2026-84281 before Fancy Product Designer stores it.

Affected sites
Not publicly reported
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
High
CVE-2026-84280

Fancy Product Designer

CVSS7.2

BitFire's WAF blocks the script-injection payloads behind CVE-2026-84280, a stored XSS flaw in Fancy Product Designer exploitable by unauthenticated attackers.

Affected sites
Not publicly reported
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-96752

Zero Spam

CVSS7.2

BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.

Affected sites
20,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
High
CVE-2026-96568

Restaurant Menu

CVSS7.2

An unauthenticated checkout field stores JavaScript that executes in admin browsers; BitFire FREE's WAF blocks the malicious POST before WordPress stores it.

Affected sites
2,000
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis

Page 2 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →