Recherche zu WordPress-Schwachstellen

Geschützte Schwachstellen.

Überprüfen Sie den Angriff hinter jeder Empfehlung und die BitFire-Kontrolle – Bot-Schutz, WAF oder Laufzeit-RASP – die verhindert, dass es zu einer Kompromittierung kommt.

Bot-Kontrollen für verifizierte Kunden Verhaltensbasierte WAF Durchsetzung von RASP zur Laufzeit
Beratungsbibliothek

Wie BitFire bekannte Schwachstellen stoppt

7–12der12-Datensätze werden angezeigt ·September 4, 2026aktualisiert

High
CVE-2026-10795

UpdraftPlus

CVSS8.1

BitFire blocks automated forged UpdraftPlus RPC requests and uses PRO RASP to prevent a malicious plugin ZIP from creating unauthorized PHP files.

Betroffene Websites
3,000,000+
Angriffsklasse
Authentication Bypass
BitFire-SchutzProtected by BitFire Bot Protection + RASP
Lesen Sie technische Analysen
Critical
CVE-2025-11749

AI Engine MCP

CVSS9.8

AI Engine exposes its MCP bearer token in public REST API discovery data, while BitFire PRO RASP prevents an MCP request authenticated only by that plugin token from creating a new administrator account.

Betroffene Websites
100,000+
Angriffsklasse
Sensitive Information Exposure
BitFire-SchutzProtected by BitFire RASP
Lesen Sie technische Analysen
Critical
CVE-2025-7340

HT Contact Form Widget

CVSS9.8

BitFire blocks CVE-2025-7340 with bot protection, WAF upload controls, and operating-system-level RASP protection against unauthorized PHP file changes.

Betroffene Websites
10,000+
Angriffsklasse
Arbitrary File Upload
BitFire-SchutzProtected by BitFire Bot Protection + WAF + RASP
Lesen Sie technische Analysen
Critical
CVE-2024-28890

Forminator

CVSS9.8

Forminator accepted files without confirming that their contents matched their apparent type, while BitFire blocks unknown exploit bots and uses PRO RASP to prevent unauthorized PHP file creation.

Betroffene Websites
600,000+
Angriffsklasse
Arbitrary File Upload
BitFire-SchutzProtected by BitFire Bot Protection + RASP
Lesen Sie technische Analysen
Critical
CVE-2024-1981

WPvivid

CVSS9.8

WPvivid exposed its staging workflow to unauthenticated requests and used the attacker-controlled table prefix in database statements, while BitFire blocks automated exploit requests, detects SQL injection, and protects sensitive database outcomes.

Betroffene Websites
900,000+
Angriffsklasse
SQL Injection
BitFire-SchutzProtected by BitFire Bot Protection + WAF
Lesen Sie technische Analysen
Critical
CVE-2024-1071

Ultimate Member

CVSS9.8

Ultimate Member lets an unauthenticated visitor inject SQL through its member-directory sorting parameter, while BitFire WAF inspects that input and rejects SQL keywords and evasion signatures before the plugin builds the query.

Betroffene Websites
200,000+
Angriffsklasse
SQL Injection
BitFire-SchutzProtected by BitFire WAF
Lesen Sie technische Analysen

Seite2von2

Schützen Sie Ihre WordPress-Website

Stoppen Sie den Vorgang, nicht nur die Signatur.

BitFire kombiniert Bot-Kontrollen, Anforderungsprüfung und Laufzeitdurchsetzung, sodass aufkommende Schwachstellen fehlschlagen, bevor eine CVE-spezifische Regel existiert.

Schützen Sie meine Website kostenlos –