Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub Single-Sign On is enabled. This can lead to complete site takeover and, when an administrator-accessible … Read more

WordPress Signs the Open Weights and American AI Leadership Letter

We’re proud to announce that WordPress has signed Open Weights and American AI Leadership, an open letter asking US policymakers to not place early restrictions on open weight AI models. These are artificial intelligence models that anyone can download, inspect, modify, and run on their own infrastructure. The letter was published on July 24, 2026, … Read more

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s password reset link, reset the account’s password, and log in as that administrator, resulting in complete site takeover. … Read more