Daily Security Intel

Archives
Log in
Subscribe
August 30, 2026

[SecurityIntel] 30 Aug | Critical WordPress Flaws and TerminalFix Campaigns Escalate

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, August 30, 2026

INTEL CONFIDENCE  60%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical WordPress Flaws and TerminalFix Campaigns Escalate

CRITICAL

0

C2 IPs

77

OTX IOCs

5

ARTICLES

■ ANALYST TLDR

A wave of critical vulnerabilities in popular WordPress plugins and themes, including GiveWP and Avada, presents an immediate threat of remote code execution and complete site takeover. Simultaneously, Microsoft has detailed "TerminalFix," a ClickFix-style campaign utilizing fake CAPTCHAs and DLL sideloading to deploy reverse tunnels on target networks. Additionally, toy manufacturer Hasbro has disclosed a data breach exposing employee personal information following a disruptive cyberattack.

■ CRITICAL STORIES

CRITICAL#1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Vulnerabilities in widely used plugins like GiveWP, Avada, and TranslatePress allow attackers to bypass authentication and execute arbitrary code, threatening thousands of websites.

HIGH#2

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Attackers are leveraging social engineering via fake CAPTCHAs and DLL sideloading to establish persistent reverse tunnels on target environments.

HIGH#3

Hasbro Data Breach Exposed Employee Personal Information

A cyberattack on the toy giant resulted in operational disruptions and the theft of sensitive employee personal data, highlighting ongoing corporate targeting.

■ CVEs IDENTIFIED

[CVE-TBD-01]

WPMU DEV Dashboard — Authentication Bypass / Account Takeover

Critical

[CVE-TBD-02]

Avada Theme — Arbitrary Code Execution (RCE)

Critical

[CVE-TBD-03]

TranslatePress — Authentication Bypass

Critical

[CVE-TBD-04]

Pods — Arbitrary Code Execution (RCE)

Critical

■ THREAT ACTORS

TerminalFix Actors

Cybercrime / Initial Access Broker

Deploying fake CAPTCHAs and DLL sideloading to establish reverse tunnels

Unknown Threat Actor

Cybercrime / Ransomware

Breached Hasbro systems, disrupting operations and stealing employee PII

■ ATT&CK TTPs

T1204.001
User Execution: Malicious Link | Users lured by fake CAPTCHA prompts in TerminalFix campaign
T1574.002
Hijack Execution Flow: DLL Side-Loading | TerminalFix campaign uses DLL sideloading for execution
T1021.001
Remote Services: Remote Desktop Protocol | Reverse tunnel established to bypass network controls
T1190
Exploit Public-Facing Application | Exploitation of critical WordPress plugin/theme vulnerabilities
T1071.001
Application Layer Protocol: Web Protocols | Reverse tunneling and C2 traffic in TerminalFix

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

GiveWP — Critical flaw allowing Remote Code Execution (RCE) — [THN]

[P1 PATCH NOW]≤24h

Avada Theme — Critical flaw allowing Arbitrary Code Execution — [THN]

[P1 PATCH NOW]≤24h

Pods — Critical flaw allowing Arbitrary Code Execution — [THN]

[P1 PATCH NOW]≤24h

WPMU DEV Dashboard — Critical flaw allowing Authentication Bypass and Account Takeover — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately update WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP plugins/themes to their latest patched versions to prevent RCE and site takeover.
2[P1] Deploy endpoint detection rules to identify DLL sideloading behaviors and unauthorized reverse tunnels associated with the TerminalFix campaign.
3[P2] Implement web filtering and user awareness training to recognize fake CAPTCHA prompts used by the TerminalFix/ClickFix campaigns.
4[P2] Hasbro should conduct comprehensive credential rotation and monitor employee PII for potential identity theft or phishing exploitation.
5[P3] Update Brave browser installations to version 1.94 to leverage the new Email Aliases feature for enhanced privacy.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 0 of 0

No C2 IPs today

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 31 Aug | TerminalFix ClickFix attacks deploy reverse-tunnel backdoors. Older → [SecurityIntel] 29 Aug | Active Exploitation of PaperCut and Cosmos EVM
Powered by Buttondown, the easiest way to start and grow your newsletter.