CVE-2026-56035
Deferred Deferred - Pending Action
Unauthenticated Multiple Vulnerabilities in BitFire

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack bitfire_security_plugin to 5.0.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress BitFire Security Plugin versions 5.0.3 and below contain multiple high-severity vulnerabilities, including an insecure design flaw classified under OWASP Top 10 A4. These vulnerabilities allow unauthenticated attackers to exploit the plugin without needing any privileges or user interaction.

Because of these flaws, attackers can launch mass campaigns targeting thousands of websites regardless of their size or popularity.

Impact Analysis

This vulnerability poses a high risk (CVSS score 8.6) as it allows unauthenticated attackers to compromise websites using the affected BitFire Security Plugin. The impact includes potential high confidentiality loss, limited integrity loss, and limited availability loss.

Exploitation could lead to unauthorized access, data breaches, or disruption of website services, affecting the security and trustworthiness of your website.

Mitigation Strategies

Users of the WordPress BitFire Security Plugin versions 5.0.3 and below are strongly advised to update immediately to version 5.0.4, which patches the multiple high-severity vulnerabilities.

Alternatively, users can apply mitigation measures such as Patchstack's auto-update or vulnerability mitigation rules to prevent potential attacks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart