chiprook
← Security
SecurityOctober 2, 2026, 20:42

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws

Four WordPress plugins were found to have CVSS 9.8 authentication bypass vulnerabilities on the same day, letting unauthenticated attackers take over administrator accounts without credentials. Wordfence blocked 137 attacks on WPMobile.App in 24 hours; patched versions are available.

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws
#WordPress#Wordfence
Read next
Security

Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass

Security

Hackers target WordPress sites via third-party WooCommerce plugin

Security

Dockhand CVE-2026-53988: CVSS 10.0 unauthenticated webhook auth bypass

Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws