WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 25–30 of 44 records · Updated September 29, 2026

Critical
CVE-2026-UNASSIGNED-CLICK2SHELL

WordPress Click2Shell

CVSS9.3

After 1,155 days of 0-day protection for every critical vulnerability - BitFire did not stop Click2Shell at disclosure. Learn why, what we deployed on September 20, and how PRO RASP protection will expand.

Affected sites
Not disclosed
Attack class
Selector Injection And Cross-site Request Forgery
BitFire protectionWAF mitigation deployed; PRO RASP hardening in evaluation
Read technical analysis
High
CVE-2026-94504

Ninja Forms

CVSS7.2

BitFire's WAF blocks the stored-script payload before Ninja Forms saves it, Bot Protection stops automated submissions, and PRO RASP contains admin fallout.

Affected sites
500,000+
Attack class
Stored Cross-site Scripting
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis
Critical
CVE-2026-92229

Forminator Forms

CVSS9.1

BitFire blocks automated Forminator exploit delivery, while PRO RASP stops privileged actions invoked through malicious shortcodes.

Affected sites
600,000+
Attack class
Arbitrary Shortcode Execution
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-9055

Amelia Premium

CVSS9.8

BitFire blocks automated Amelia endpoint abuse, while PRO RASP prevents unauthorized role changes and administrator password takeover.

Affected sites
<80,000
Attack class
Privilege Escalation
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-78159

The Events Calendar

CVSS9.8

BitFire blocks automated Events Calendar exploit delivery, while PRO RASP prevents unauthorized PHP files and administrator persistence.

Affected sites
600,000
Attack class
Callable Injection
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-12793

JetFormBuilder

CVSS9.8

BitFire blocks automated JetFormBuilder exploit delivery, while PRO RASP prevents unauthorized administrator account creation.

Affected sites
80,000
Attack class
Improper Authorization
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis

Page 5 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →