AI Engine exposes its MCP bearer token in public REST API discovery data, while BitFire PRO RASP prevents an MCP request authenticated only by that plugin token from creating a new administrator account.
Forminator accepted files without confirming that their contents matched their apparent type, while BitFire blocks unknown exploit bots and uses PRO RASP to prevent unauthorized PHP file creation.
Affected sites
600,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + RASP
WPvivid exposed its staging workflow to unauthenticated requests and used the attacker-controlled table prefix in database statements, while BitFire blocks automated exploit requests, detects SQL injection, and protects sensitive database outcomes.
Affected sites
900,000+
Attack class
SQL Injection
BitFire protectionProtected by BitFire Bot Protection + WAF
Ultimate Member lets an unauthenticated visitor inject SQL through its member-directory sorting parameter, while BitFire WAF inspects that input and rejects SQL keywords and evasion signatures before the plugin builds the query.