WordPress 漏洞研究

受保护的漏洞。

检查每个建议和 BitFire 控制(机器人防护、WAF 或运行时 RASP)背后的攻击,以防止其成为威胁。

已验证的客户端机器人控制 基于行为的WAF 运行时 RASP 实施
咨询图书馆

BitFire 如何阻止已知漏洞

Showing 1–6 of 44 records · Updated September 29, 2026

High
CVE-2026-96326

HT Contact Form

CVSS7.2

BitFire FREE Bot Protection stops the scripted submission that delivers CVE-2026-96326 and the WAF strips its XSS payload before WordPress runs.

受影响的站点
10000
攻击等级
Stored Cross-site Scripting
BitFire 保护Secure with BitFire WAF + BitFire Bot Protection
阅读技术分析
High
CVE-2026-87741

ConvertPlus

CVSS8.8

BitFire Bot Protection blocks the automated AJAX delivery CVE-2026-87741 depends on, stopping ConvertPlus PHP object injection before vulnerable code runs.

受影响的站点
Not publicly reported
攻击等级
Deserialization Of Untrusted Data
BitFire 保护Protected by BitFire Bot Protection
阅读技术分析
Medium
CVE-2026-15273

Automatic.css

CVSS6.4

BitFire's WAF inspects request URLs and blocks the Cross-Site Scripting payloads CVE-2026-15273 lets attackers store in Automatic.css 4.0.0.

受影响的站点
Not publicly reported
攻击等级
Stored Cross-site Scripting
BitFire 保护Secure with BitFire WAF
阅读技术分析
High
CVE-2026-96039

BA Book Everything

CVSS7.2

BitFire FREE Bot Protection and WAF stop CVE-2026-96039, an unauthenticated stored XSS chain in BA Book Everything, before the payload ever reaches WordPress.

受影响的站点
10000
攻击等级
Stored Cross-site Scripting
BitFire 保护Secure with BitFire WAF + BitFire Bot Protection
阅读技术分析
Medium
CVE-2026-92799

Bookly

CVSS5.3

BitFire FREE Bot Protection and BitFire PRO RASP stop the unauthenticated CVE-2026-92799 Bookly verification bypass that overwrites customer records.

受影响的站点
60000
攻击等级
Type Juggling Authorization Bypass
BitFire 保护Secure with BitFire PRO RASP + BitFire Bot Protection
阅读技术分析
High
CVE-2026-92713

Modula Image Gallery

CVSS8.1

BitFire FREE Bot Protection stops the automated REST delivery of CVE-2026-92713, the Modula Image Gallery Author-level arbitrary file deletion flaw.

受影响的站点
100000
攻击等级
Missing Authorization
BitFire 保护Protected by BitFire Bot Protection
阅读技术分析

第 1 页,共 8 页

保护您的 WordPress 网站

停止操作,而不仅仅是签名。

BitFire 结合了机器人控制、请求检查和运行时执行,因此新出现的漏洞会在特定于 CVE 的规则存在之前失败。

免费保护我的网站 →