WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 7–10 of 10 records · Updated July 30, 2026

Critical
CVE-2025-7340

HT Contact Form Widget

CVSS9.8

BitFire blocks CVE-2025-7340 with bot protection, WAF upload controls, and operating-system-level RASP protection against unauthorized PHP file changes.

Affected sites
10,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + WAF + RASP
Read technical analysis
Critical
CVE-2024-28890

Forminator

CVSS9.8

Forminator accepted files without confirming that their contents matched their apparent type, while BitFire blocks unknown exploit bots and uses PRO RASP to prevent unauthorized PHP file creation.

Affected sites
600,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis
Critical
CVE-2024-1981

WPvivid

CVSS9.8

WPvivid exposed its staging workflow to unauthenticated requests and used the attacker-controlled table prefix in database statements, while BitFire blocks automated exploit requests, detects SQL injection, and protects sensitive database outcomes.

Affected sites
900,000+
Attack class
SQL Injection
BitFire protectionProtected by BitFire Bot Protection + WAF
Read technical analysis
Critical
CVE-2024-1071

Ultimate Member

CVSS9.8

Ultimate Member lets an unauthenticated visitor inject SQL through its member-directory sorting parameter, while BitFire WAF inspects that input and rejects SQL keywords and evasion signatures before the plugin builds the query.

Affected sites
200,000+
Attack class
SQL Injection
BitFire protectionProtected by BitFire WAF
Read technical analysis

Page 2 of 2

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →