WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 1–6 of 44 records · Updated September 29, 2026

High
CVE-2026-96326

HT Contact Form

CVSS7.2

BitFire FREE Bot Protection stops the scripted submission that delivers CVE-2026-96326 and the WAF strips its XSS payload before WordPress runs.

Affected sites
10000
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
High
CVE-2026-87741

ConvertPlus

CVSS8.8

BitFire Bot Protection blocks the automated AJAX delivery CVE-2026-87741 depends on, stopping ConvertPlus PHP object injection before vulnerable code runs.

Affected sites
Not publicly reported
Attack class
Deserialization Of Untrusted Data
BitFire protectionProtected by BitFire Bot Protection
Read technical analysis
Medium
CVE-2026-15273

Automatic.css

CVSS6.4

BitFire's WAF inspects request URLs and blocks the Cross-Site Scripting payloads CVE-2026-15273 lets attackers store in Automatic.css 4.0.0.

Affected sites
Not publicly reported
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-96039

BA Book Everything

CVSS7.2

BitFire FREE Bot Protection and WAF stop CVE-2026-96039, an unauthenticated stored XSS chain in BA Book Everything, before the payload ever reaches WordPress.

Affected sites
10000
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
Medium
CVE-2026-92799

Bookly

CVSS5.3

BitFire FREE Bot Protection and BitFire PRO RASP stop the unauthenticated CVE-2026-92799 Bookly verification bypass that overwrites customer records.

Affected sites
60000
Attack class
Type Juggling Authorization Bypass
BitFire protectionSecure with BitFire PRO RASP + BitFire Bot Protection
Read technical analysis
High
CVE-2026-92713

Modula Image Gallery

CVSS8.1

BitFire FREE Bot Protection stops the automated REST delivery of CVE-2026-92713, the Modula Image Gallery Author-level arbitrary file deletion flaw.

Affected sites
100000
Attack class
Missing Authorization
BitFire protectionProtected by BitFire Bot Protection
Read technical analysis

Page 1 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →