Executive brief
BitFire Security, a security plugin for WordPress websites, contains multiple vulnerabilities that can be exploited by unauthenticated attackers. These flaws could allow an attacker to compromise the security of the website, potentially leading to unauthorized data access or service disruption. Organizations using this plugin should update to the latest version immediately to protect their web operations and customer data.
Technical details
BitFire Security (a WordPress plugin) versions up to and including 5.0.3 are subject to multiple vulnerabilities, including issues related to improper validation of specified quantities in input (CWE-1284). These vulnerabilities are exploitable by a remote, unauthenticated attacker over the network without any user interaction. The combined impact of these flaws allows for high confidentiality impact and low integrity and availability impact. The issues have been addressed in version 5.0.4.
Affected products
- Cory Marsh BitFire Security <= 5.0.3
Timeline
- 2026-05-27: other: Reported by Aurélien BOURDOIS (Elymaro)
- 2026-06-23: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD