WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 1–6 of 30 records · Updated September 25, 2026

High
CVE-2026-96752

Zero Spam

CVSS7.2

BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.

Affected sites
20,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis
Medium
CVE-2026-93747

wpForo Forum

CVSS6.4

BitFire's WAF blocks the wpForo CVE-2026-93747 stored XSS payload at the request layer, before it is stored or ever rendered to an admin.

Affected sites
20,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVSS7.1

BitFire FREE blocks the double-encoded traversal before vulnerable WordPress template resolution can include an attacker-selected PHP file.

Affected sites
+100,000,000
Attack class
Path Traversal And Local File Inclusion
BitFire protectionProtected by BitFire Bot Protection + WAF
Read technical analysis
High

BitFire FREE blocks the double-encoded traversal local file inclusion before vulnerable WordPress template resolution can include an attacker-selected PHP file.

Affected sites
+100,000,000
Attack class
Path Traversal And Local File Inclusion
BitFire protectionProtected by BitFire Bot Protection + WAF
Read technical analysis
Critical
CVE-2026-82222

GiveWP

CVSS9.8

BitFire FREE detects the serialized PHP object behind CVE-2026-82222 before GiveWP can deserialize it and trigger remote code execution.

Affected sites
100,000+
Attack class
Php Object Injection
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis
Critical
CVE-2026-18781

Drag and Drop CF7 Upload

CVSS9.8

BitFire blocks malicious uploads and PRO RASP prevents unauthorized PHAR creation through the vulnerable Contact Form 7 add-on.

Affected sites
60,000
Attack class
Unrestricted File Upload
BitFire protectionProtected by BitFire Bot Protection + WAF + PRO RASP
Read technical analysis

Page 1 of 5

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →