WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 1–6 of 17 records · Updated September 21, 2026

Unrated
CVE-2026-xxxxx

ACF Extended PRO

CVSS

BitFire PRO RASP blocks protected takeover and persistence outcomes from ACF Extended PRO limited code injection.

Affected sites
Not disclosed
Attack class
Limited Code Injection
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-92229

Forminator Forms

CVSS9.1

BitFire blocks automated Forminator exploit delivery, while PRO RASP stops privileged actions invoked through malicious shortcodes.

Affected sites
600,000+
Attack class
Arbitrary Shortcode Execution
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-78159

The Events Calendar

CVSS9.8

BitFire blocks automated Events Calendar exploit delivery, while PRO RASP prevents unauthorized PHP files and administrator persistence.

Affected sites
600,000
Attack class
Callable Injection
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-12793

JetFormBuilder

CVSS9.8

BitFire blocks automated JetFormBuilder exploit delivery, while PRO RASP prevents unauthorized administrator account creation.

Affected sites
80,000
Attack class
Improper Authorization
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-83627

ComboBlocks

CVSS9.8

BitFire PRO RASP contains protected takeover and persistence outcomes from unauthenticated WordPress hook injection.

Affected sites
70,000
Attack class
Unauthenticated Hook Injection
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-15748

Forminator Forms

CVSS9.8

BitFire blocks automated Forminator submission exploits and uses PRO RASP to prevent CVE-2026-15748 from creating unauthorized PHP files.

Affected sites
600,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis

Page 1 of 3

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →