Recherche zu WordPress-Schwachstellen

Geschützte Schwachstellen.

Überprüfen Sie den Angriff hinter jeder Empfehlung und die BitFire-Kontrolle – Bot-Schutz, WAF oder Laufzeit-RASP – die verhindert, dass es zu einer Kompromittierung kommt.

Bot-Kontrollen für verifizierte Kunden Verhaltensbasierte WAF Durchsetzung von RASP zur Laufzeit
Beratungsbibliothek

Wie BitFire bekannte Schwachstellen stoppt

25–30der44-Datensätze werden angezeigt ·September 29, 2026aktualisiert

Critical
CVE-2026-UNASSIGNED-CLICK2SHELL

WordPress Click2Shell

CVSS9.3

After 1,155 days of 0-day protection for every critical vulnerability - BitFire did not stop Click2Shell at disclosure. Learn why, what we deployed on September 20, and how PRO RASP protection will expand.

Betroffene Websites
Not disclosed
Angriffsklasse
Selector Injection And Cross-site Request Forgery
BitFire-SchutzWAF mitigation deployed; PRO RASP hardening in evaluation
Lesen Sie technische Analysen
High
CVE-2026-94504

Ninja Forms

CVSS7.2

BitFire's WAF blocks the stored-script payload before Ninja Forms saves it, Bot Protection stops automated submissions, and PRO RASP contains admin fallout.

Betroffene Websites
500,000+
Angriffsklasse
Stored Cross-site Scripting
BitFire-SchutzProtected by BitFire Bot Protection + WAF + PRO RASP
Lesen Sie technische Analysen
Critical
CVE-2026-92229

Forminator Forms

CVSS9.1

BitFire blocks automated Forminator exploit delivery, while PRO RASP stops privileged actions invoked through malicious shortcodes.

Betroffene Websites
600,000+
Angriffsklasse
Arbitrary Shortcode Execution
BitFire-SchutzProtected by BitFire Bot Protection + PRO RASP
Lesen Sie technische Analysen
Critical
CVE-2026-9055

Amelia Premium

CVSS9.8

BitFire blocks automated Amelia endpoint abuse, while PRO RASP prevents unauthorized role changes and administrator password takeover.

Betroffene Websites
<80,000
Angriffsklasse
Privilege Escalation
BitFire-SchutzProtected by BitFire Bot Protection + PRO RASP
Lesen Sie technische Analysen
Critical
CVE-2026-78159

The Events Calendar

CVSS9.8

BitFire blocks automated Events Calendar exploit delivery, while PRO RASP prevents unauthorized PHP files and administrator persistence.

Betroffene Websites
600,000
Angriffsklasse
Callable Injection
BitFire-SchutzProtected by BitFire Bot Protection + PRO RASP
Lesen Sie technische Analysen
Critical
CVE-2026-12793

JetFormBuilder

CVSS9.8

BitFire blocks automated JetFormBuilder exploit delivery, while PRO RASP prevents unauthorized administrator account creation.

Betroffene Websites
80,000
Angriffsklasse
Improper Authorization
BitFire-SchutzProtected by BitFire Bot Protection + PRO RASP
Lesen Sie technische Analysen

Seite5von8

Schützen Sie Ihre WordPress-Website

Stoppen Sie den Vorgang, nicht nur die Signatur.

BitFire kombiniert Bot-Kontrollen, Anforderungsprüfung und Laufzeitdurchsetzung, sodass aufkommende Schwachstellen fehlschlagen, bevor eine CVE-spezifische Regel existiert.

Schützen Sie meine Website kostenlos –