WordPress News: Critical Plugin and Theme Vulnerabilities Patched (Week of 1 September 2026)

This was a week where the WordPress ecosystem's biggest names had to own up to serious problems. A best-selling theme shipped a remote code execution chain, a popular management plugin had an authentication bypass, and a household-name caching plugin admitted it sat on a bug report for six weeks before it took sites offline. None of this is filler news: if you use any of the products below, there's a real action to take.
Update Avada and Fusion Builder immediately
Security researchers at Wordfence found and confirmed a critical, unauthenticated remote code execution vulnerability in Avada, one of the best-selling WordPress themes ever, with over a million sales, when used with its bundled Fusion Builder plugin. The flaw (CVE-2026-18431, CVSS 9.8) chains six separate weaknesses together so an attacker with no login and no user interaction from a victim can write and execute PHP files on your server. It only works if both Avada and Fusion Builder are active, but between them that's most Avada sites. It's worth saying plainly: this took six weaknesses lined up in an exact order to pull off, more Death Star trench run than smash-and-grab, but the vendor ThemeFusion has patched it all in Avada 7.16.1 and Fusion Builder 3.16.1, released 25 August 2026.
What this means for you: if your site runs Avada, update both the theme and Fusion Builder to the latest version today. Don't wait for a maintenance window. If you're not sure which theme your site uses, ask your developer or host to check. For general hardening advice while you're in there, see our guide to WordPress security best practices.
Patch WPMU DEV Dashboard if you use Hub SSO
Wordfence also disclosed a critical authentication bypass in the WPMU DEV Dashboard plugin, installed on an estimated 350,000 sites (CVE-2026-76581, CVSS 9.8). The bug lets an unauthenticated attacker forge a valid login token and gain full administrator access, but only on sites where Hub Single Sign-On is enabled and mapped to an admin account. WPMU DEV moved fast: the report landed 19 August 2026 and the patched version 5.0.2 was public by 24 August.
What this means for you: if you don't use WPMU DEV Dashboard, or you do but don't have Hub SSO switched on, you're fine. If you do have Hub SSO enabled, update to 5.0.2 now, and if you can't update immediately, turn Hub SSO off until you can. A quick backup before any update is cheap insurance; our guide on backups done right covers what a proper backup routine actually looks like.
The WP Rocket lesson: test before you auto-update
Not every story this week is about attackers. When WordPress 7.1 shipped on 19 August, sites running the popular WP Rocket caching plugin alongside certain other plugins (Elementor Pro and Contact Form 7 Redirection among them) started throwing fatal errors within hours. WP Rocket published a post-mortem admitting the root cause had been reported on GitHub six weeks earlier, with a working fix already suggested, but the report was never assigned to anyone and the ticket went quiet. The company estimates around 10% of its user base was actually affected. A fix shipped in version 3.23.2.2, and WP Rocket says it's rebuilding its test suite around the plugins people actually run alongside it.
What this means for you: if you use WP Rocket, confirm you're on 3.23.2.2 or later before touching anything else. More broadly, this is a good reminder not to let major WordPress core updates auto-apply to a live site without testing first. A staging copy catches exactly this kind of interaction bug before your customers see it; our piece on staging sites walks through setting one up. If a critical error does knock your site offline in the meantime, our critical error guide has the fast fixes.
The wrap-up
Three stories, three different lessons: patch fast when a critical flaw hits a product you actually use, don't panic when it doesn't apply to you, and test before you update. None of this is dramatic if you're already on top of updates, which is really the whole point. If keeping up with this kind of thing isn't how you want to spend your week, a proper maintenance plan handles the updates, patching, and monitoring for you automatically, so stories like these become "already handled" rather than "urgent to-do."
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


