WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 13–18 of 30 records · Updated September 25, 2026

Critical
CVE-2026-92229

Forminator Forms

CVSS9.1

BitFire blocks automated Forminator exploit delivery, while PRO RASP stops privileged actions invoked through malicious shortcodes.

Affected sites
600,000+
Attack class
Arbitrary Shortcode Execution
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-9055

Amelia Premium

CVSS9.8

BitFire blocks automated Amelia endpoint abuse, while PRO RASP prevents unauthorized role changes and administrator password takeover.

Affected sites
<80,000
Attack class
Privilege Escalation
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-78159

The Events Calendar

CVSS9.8

BitFire blocks automated Events Calendar exploit delivery, while PRO RASP prevents unauthorized PHP files and administrator persistence.

Affected sites
600,000
Attack class
Callable Injection
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-12793

JetFormBuilder

CVSS9.8

BitFire blocks automated JetFormBuilder exploit delivery, while PRO RASP prevents unauthorized administrator account creation.

Affected sites
80,000
Attack class
Improper Authorization
BitFire protectionProtected by BitFire Bot Protection + PRO RASP
Read technical analysis
Critical
CVE-2026-83627

ComboBlocks

CVSS9.8

BitFire PRO RASP contains protected takeover and persistence outcomes from unauthenticated WordPress hook injection.

Affected sites
70,000
Attack class
Unauthenticated Hook Injection
BitFire protectionProtected by BitFire PRO RASP
Read technical analysis
Critical
CVE-2026-15748

Forminator Forms

CVSS9.8

BitFire blocks automated Forminator submission exploits and uses PRO RASP to prevent CVE-2026-15748 from creating unauthorized PHP files.

Affected sites
600,000+
Attack class
Arbitrary File Upload
BitFire protectionProtected by BitFire Bot Protection + RASP
Read technical analysis

Page 3 of 5

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →