WordPress vulnerability research

Protected vulnerabilities.

Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.

Verified-client bot controls Behavior-based WAF Runtime RASP enforcement
Advisory library

How BitFire stops known vulnerabilities

Showing 1–6 of 39 records · Updated September 26, 2026

High
CVE-2026-92713

Modula Image Gallery

CVSS8.1

BitFire FREE Bot Protection stops the automated REST delivery of CVE-2026-92713, the Modula Image Gallery Author-level arbitrary file deletion flaw.

Affected sites
100000
Attack class
Missing Authorization
BitFire protectionProtected by BitFire Bot Protection
Read technical analysis
Medium
CVE-2026-92212

JetFormBuilder

CVSS6.1

BitFire's FREE WAF blocks the malicious query-string payloads behind the JetFormBuilder CVE-2026-92212 reflected XSS before WordPress processes the request.

Affected sites
80000
Attack class
Reflected Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-89426

Knit Pay

CVSS8.8

CVE-2026-89426 lets any Knit Pay 9.6.1.0 user become administrator via Gravity Forms. BitFire FREE Bot Protection and PRO RASP stop the chain.

Affected sites
2000
Attack class
Broken Access Control
BitFire protectionSecure with BitFire PRO RASP + BitFire Bot Protection
Read technical analysis
High
CVE-2026-84280

Fancy Product Designer

CVSS7.2

BitFire's WAF blocks the script-injection payloads behind CVE-2026-84280, a stored XSS flaw in Fancy Product Designer exploitable by unauthenticated attackers.

Affected sites
Not publicly reported
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
Medium
CVE-2026-15273

Automatic.css

CVSS6.4

BitFire's WAF inspects request URLs and blocks the unauthenticated stored XSS payload CVE-2026-15273 injects through REQUEST_URI in Automatic.css 4.0.0.

Affected sites
Not publicly reported
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF
Read technical analysis
High
CVE-2026-96752

Zero Spam

CVSS7.2

BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.

Affected sites
20,000+
Attack class
Stored Cross-site Scripting
BitFire protectionSecure with BitFire WAF + BitFire Bot Protection
Read technical analysis

Page 1 of 7

Protect your WordPress website

Stop the operation, not only the signature.

BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.

Protect my site free →