WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 37–42 of 44 records · Updated September 29, 2026

Critical
CVE-2026-5524

Divi Form Builder

CVSS9.8

BitFire blocks automated CVE-2026-5524 upload requests and uses PRO RASP to prevent Divi Form Builder from creating unauthorized executable PHP files.

Affected sites
2,600,000
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire RASP
Read technical analysis
Critical
CVE-2026-15158

Blocksy Companion Pro

CVSS9.8

BitFire blocks automated exploit requests and uses PRO RASP to prevent CVE-2026-15158 from creating an unauthorized PHP file through Blocksy Companion Pro.

Affected sites
300,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by RASP
Read technical analysis
High
CVE-2026-10795

UpdraftPlus

CVSS8.1

BitFire blocks automated forged UpdraftPlus RPC requests and uses PRO RASP to prevent a malicious plugin ZIP from creating unauthorized PHP files.

Affected sites
3,000,000+
Attack class
Authentication Bypass
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis
Critical
CVE-2025-11749

AI Engine MCP

CVSS9.8

AI Engine exposes its MCP bearer token in public REST API discovery data, while BitFire PRO RASP prevents an MCP request authenticated only by that plugin token from creating a new administrator account.

Affected sites
100,000+
Attack class
Sensitive Information Exposure
BitFire protectionProtected by BitFire RASP
Read technical analysis
Critical
CVE-2025-7340

HT Contact Form Widget

CVSS9.8

BitFire blocks CVE-2025-7340 with bot protection, WAF upload controls, and operating-system-level RASP protection against unauthorized PHP file changes.

Affected sites
10,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + WAF + RASP
Read technical analysis
Critical
CVE-2024-28890

Forminator

CVSS9.8

Forminator accepted files without confirming that their contents matched their apparent type, while BitFire blocks unknown exploit bots and uses PRO RASP to prevent unauthorized PHP file creation.

Affected sites
600,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis

Page 7 of 8

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →