WordPress 漏洞研究

受保护的漏洞。

检查每个建议和 BitFire 控制(机器人防护、WAF 或运行时 RASP)背后的攻击,以防止其成为威胁。

已验证的客户端机器人控制 基于行为的WAF 运行时 RASP 实施
咨询图书馆

BitFire 如何阻止已知漏洞

Showing 13–18 of 44 records · Updated September 29, 2026

High
CVE-2026-95864

Themify Builder

CVSS7.2

BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX request behind CVE-2026-95864 before it stores script on your site.

受影响的站点
5,000+
攻击等级
Stored Cross-site Scripting
BitFire 保护Secure with BitFire WAF + BitFire Bot Protection
阅读技术分析
Medium
CVE-2026-93747

wpForo Forum

CVSS6.4

BitFire's WAF blocks the wpForo CVE-2026-93747 stored XSS payload at the request layer, before it is stored or ever rendered to an admin.

受影响的站点
20,000+
攻击等级
Stored Cross-site Scripting
BitFire 保护Secure with BitFire WAF
阅读技术分析
Medium
CVE-2026-93656

Profile Builder

CVSS6.4

BitFire's FREE WAF blocks CVE-2026-93656's payload-bearing request before Profile Builder can persist it or an administrator's browser can run it.

受影响的站点
40,000+
攻击等级
Cross-site Scripting
BitFire 保护Secure with BitFire WAF
阅读技术分析
High
CVE-2026-93303

HT Contact Form

CVSS7.2

BitFire's WAF detects and blocks the unauthenticated stored DOM-based XSS payload in HT Contact Form ≤ 2.10.1 before WordPress processes the request.

受影响的站点
10,000+
攻击等级
Stored Dom-based Cross-site Scripting
BitFire 保护Secure with BitFire WAF
阅读技术分析
High
CVSS7.1

BitFire FREE blocks the double-encoded traversal before vulnerable WordPress template resolution can include an attacker-selected PHP file.

受影响的站点
+100,000,000
攻击等级
Path Traversal And Local File Inclusion
BitFire 保护Protected by BitFire Bot Protection + WAF
阅读技术分析
High

BitFire FREE blocks the double-encoded traversal local file inclusion before vulnerable WordPress template resolution can include an attacker-selected PHP file.

受影响的站点
+100,000,000
攻击等级
Path Traversal And Local File Inclusion
BitFire 保护Protected by BitFire Bot Protection + WAF
阅读技术分析

第 3 页,共 8 页

保护您的 WordPress 网站

停止操作,而不仅仅是签名。

BitFire 结合了机器人控制、请求检查和运行时执行,因此新出现的漏洞会在特定于 CVE 的规则存在之前失败。

免费保护我的网站 →