WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 13–18 of 44 records · Updated September 29, 2026

High
CVE-2026-95864

Themify Builder

CVSS7.2

BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX request behind CVE-2026-95864 before it stores script on your site.

Affected sites
5,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
Medium
CVE-2026-93747

wpForo Forum

CVSS6.4

BitFire's WAF blocks the wpForo CVE-2026-93747 stored XSS payload at the request layer, before it is stored or ever rendered to an admin.

Affected sites
20,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
Medium
CVE-2026-93656

Profile Builder

CVSS6.4

BitFire's FREE WAF blocks CVE-2026-93656's payload-bearing request before Profile Builder can persist it or an administrator's browser can run it.

Affected sites
40,000+
Attack class
Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-93303

HT Contact Form

CVSS7.2

BitFire's WAF detects and blocks the unauthenticated stored DOM-based XSS payload in HT Contact Form ≤ 2.10.1 before WordPress processes the request.

Affected sites
10,000+
Attack class
Stored Dom-based Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVSS7.1

BitFire FREE blocks the double-encoded traversal before vulnerable WordPress template resolution can include an attacker-selected PHP file.

Affected sites
+100,000,000
Attack class
Path Traversal And Local File Inclusion
BitFire protectionProtected by BitFire Bot Protection + WAF
Read technical analysis
High

BitFire FREE blocks the double-encoded traversal local file inclusion before vulnerable WordPress template resolution can include an attacker-selected PHP file.

Affected sites
+100,000,000
Attack class
Path Traversal And Local File Inclusion
BitFire protectionProtected by BitFire Bot Protection + WAF
Read technical analysis

Page 3 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →