Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical vulnerabilities affecting popular WordPress plugins and themes—including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—have been disclosed by Wordfence and Patchstack researchers. These flaws enable attackers to bypass authentication, take over accounts, and achieve arbitrary code execution on affected WordPress installations. The most severe vulnerability has a CVSS score of 9.8, representing an immediate threat to site integrity and data security.
A security researcher discovered multiple vulnerabilities in the Unitree G1 humanoid robot that allow remote root access without physical interaction, and demonstrated how a compromised unit could be weaponized to attack neighboring robots. By chaining two separate flaws together, the researcher established a concerning attack vector that reveals the propagation risks within networked robotic systems. The three-month investigation highlights significant security gaps in the robot's design that could have broad implications for deployments in shared or industrial environments.
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
Cosmos Labs disclosed that a critical balance-handling vulnerability in its shared EVM module was actively exploited to drain funds from six blockchains over a five-day period in August 2026, despite the company's awareness that every blockchain using the module was vulnerable. The flaw, tracked as GHSA-7g4w-cg88-2cq2, was published without standard vulnerability identifiers or severity scoring, complicating threat assessment and response coordination across affected networks.
Attackers are chaining two vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution by compromising the application's trusted configuration. PaperCut has released an emergency patch with additional hardening measures to address the flaw. The vulnerability allows malicious actors to execute arbitrary Java code within the application without requiring authentication credentials.