WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 7–12 of 30 records · Updated September 25, 2026

Critical
CVE-2026-18431

Avada + Fusion Builder

CVSS9.8

BitFire PRO RASP blocks unauthorized PHP-file writes that turn the Avada and Fusion Builder flaw into persistent server compromise.

Affected sites
700,000+
Attack class
Arbitrary File Write
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-18052

ManageWP Worker

CVSS9.8

ManageWP Worker authentication bypass can log attackers in as other users, while BitFire PRO RASP blocks unauthorized session creation.

Affected sites
1,000,900+
Attack class
Authentication Bypass
BitFire protectionProtected by PRO RASP
Read technical analysis
Critical
CVE-2026-12526

ACF Extended

CVSS9.8

BitFire PRO RASP blocks unauthorized administrator password changes that turn CVE-2026-12526 into account takeover.

Affected sites
2,000,000+
Attack class
Privilege Escalation
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Unrated
CVE-2026-xxxxx

ACF Extended PRO

CVSS—

BitFire PRO RASP blocks protected takeover and persistence outcomes from ACF Extended PRO limited code injection.

Affected sites
Not disclosed
Attack class
Limited Code Injection
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-UNASSIGNED-CLICK2SHELL

WordPress Click2Shell

CVSS9.3

After 1,155 days of 0-day protection for every critical vulnerability - BitFire did not stop Click2Shell at disclosure. Learn why, what we deployed on September 20, and how PRO RASP protection will expand.

Affected sites
Not disclosed
Attack class
Selector Injection And Cross-site Request Forgery
BitFire protectionWAF mitigation deployed; PRO RASP hardening in evaluation
Read technical analysis
High
CVE-2026-94504

Ninja Forms

CVSS7.2

BitFire's WAF blocks the stored-script payload before Ninja Forms saves it, Bot Protection stops automated submissions, and PRO RASP contains admin fallout.

Affected sites
500,000+
Attack class
Stored Cross-site Scripting
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis

Page 2 of 5

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →