WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 1–6 of 10 records · Updated July 30, 2026

Critical
CVSS9.1

BitFire RASP blocks CVE-2026-14488 at the database layer by preventing users without the required WordPress capabilities from deleting posts and pages.

Affected sites
600,000+
Attack class
Missing Authorization
BitFire protectionProtected by BitFire RASP
Read technical analysis
Critical

BitFire blocks CVE-2026-63030 with verified-browser POST protection, SQL injection detection, and RASP prevention of administrator account creation.

Affected sites
500,000,000+
Attack class
Sql Injection
BitFire protectionProtected by BitFire Bot Protection + WAF + RASP
Read technical analysis
Critical
CVE-2026-5524

Divi Form Builder

CVSS9.8

BitFire blocks automated CVE-2026-5524 upload requests and uses PRO RASP to prevent Divi Form Builder from creating unauthorized executable PHP files.

Affected sites
2,600,000
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire RASP
Read technical analysis
Critical
CVE-2026-15158

Blocksy Companion Pro

CVSS9.8

BitFire blocks automated exploit requests and uses PRO RASP to prevent CVE-2026-15158 from creating an unauthorized PHP file through Blocksy Companion Pro.

Affected sites
300,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by RASP
Read technical analysis
High
CVE-2026-10795

UpdraftPlus

CVSS8.1

BitFire blocks automated forged UpdraftPlus RPC requests and uses PRO RASP to prevent a malicious plugin ZIP from creating unauthorized PHP files.

Affected sites
3,000,000+
Attack class
Authentication Bypass
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis
Critical
CVE-2025-11749

AI Engine MCP

CVSS9.8

AI Engine exposes its MCP bearer token in public REST API discovery data, while BitFire PRO RASP prevents an MCP request authenticated only by that plugin token from creating a new administrator account.

Affected sites
100,000+
Attack class
Sensitive Information Exposure
BitFire protectionProtected by BitFire RASP
Read technical analysis

Page 1 of 2

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →