WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 19–24 of 44 records · Updated September 29, 2026

Critical
CVE-2026-82222

GiveWP

CVSS9.8

BitFire FREE detects the serialized PHP object behind CVE-2026-82222 before GiveWP can deserialize it and trigger remote code execution.

Affected sites
100,000+
Attack class
Php Object Injection
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis
Critical
CVE-2026-18781

Drag and Drop CF7 Upload

CVSS9.8

BitFire blocks malicious uploads and PRO RASP prevents unauthorized PHAR creation through the vulnerable Contact Form 7 add-on.

Affected sites
60,000
Attack class
Unrestricted File Upload
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis
Critical
CVE-2026-18431

Avada + Fusion Builder

CVSS9.8

BitFire PRO RASP blocks unauthorized PHP-file writes that turn the Avada and Fusion Builder flaw into persistent server compromise.

Affected sites
700,000+
Attack class
Arbitrary File Write
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-18052

ManageWP Worker

CVSS9.8

ManageWP Worker authentication bypass can log attackers in as other users, while BitFire PRO RASP blocks unauthorized session creation.

Affected sites
1,000,900+
Attack class
Authentication Bypass
BitFire protectionProtected by PRO RASP
Read technical analysis
Critical
CVE-2026-12526

ACF Extended

CVSS9.8

BitFire PRO RASP blocks unauthorized administrator password changes that turn CVE-2026-12526 into account takeover.

Affected sites
2,000,000+
Attack class
Privilege Escalation
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Unrated
CVE-2026-xxxxx

ACF Extended PRO

CVSS—

BitFire PRO RASP blocks protected takeover and persistence outcomes from ACF Extended PRO limited code injection.

Affected sites
Not disclosed
Attack class
Limited Code Injection
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis

Page 4 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →