WAF Weekly: WordPress RCEs, Norway DDoS, AI patching, Sep 4 2026
A WordPress migration plugin RCE exposes millions of sites, Elementor Pro is exploited in the wild, a DDoS attack disrupts Norwegian government services, and Cloudflare and CrowdSec push WAF intelligence forward with AI and bot detection.
All-in-One WP Migration RCE Puts Millions of Sites at Risk
A high-severity flaw in the All-in-One WP Migration and Backup plugin leaves around 3.2 million WordPress sites vulnerable to remote code execution. Tracked as CVE-2026-19949 (CVSS 8.8), it is a second-order SQL injection in the archive restore flow. An attacker can smuggle content through WordPress trackbacks to lift the restore secret key, then import a crafted archive that drops a malicious must-use plugin. Version 7.110 patched it on August 20, but only 35 percent of installs have updated. This is the kind of exposed restore surface a WordPress WAF is built to virtual patch while admins catch up.
Elementor Pro Exploited in the Wild
Wordfence reported that attackers are actively exploiting a critical vulnerability in Elementor Pro, one of the most widely installed WordPress commercial plugins. The campaign uses the flaw for site compromise before many sites can apply a fix. Elementor's massive install base makes this a real scan-and-exploit target. It underscores why edge and in-app Wordfence virtual patching matters for busy plugin ecosystems where updates lag behind disclosure.
DDoS Attack Ties Up Norwegian Government Services
A sustained DDoS campaign hit the Norwegian digitalization agency Digdir, disrupting the ID-porten identity gateway, Altinn, e-formidling, and digital mailboxes since late August. This is the third time Digdir and subcontractor Vivicta have been hit in a short window. No breach or data loss was reported, but the attacks turned availability into a weapon against critical public infrastructure. A single authentication chokepoint used by an entire country demands hardened edge DDoS and WAF capacity, not just during an incident.
China-Linked Fire Ant Hijacks Cisco Routers
Researchers flagged a China-linked group, Fire Ant, hijacking Cisco routers to steal credentials and blind security logging. By compromising network equipment at scale, the group can reroute traffic and hide from defenders inside the perimeter. Network device compromise is exactly what a WAF cannot see on its own, which is why segmentation, remote logging, and monitoring edge-to-network is essential alongside web-layer defenses.
Cloudflare Brings WAF Context to AI Vulnerability Discovery
Cloudflare announced early access to Vulnerability Discovery and Remediation, an invitation-only service under Managed Defense. It combines Web Assets and WAF data with OpenAI Daybreak models like GPT-5.6 Cyber to find security, prioritize by real production traffic and attack activity, and propose both code patches and scoped WAF custom rules. The core idea is promising and deeply relevant to WAFs: the security context of live routes turns generic scanner findings into evidence-based priorities. It also shows WAF rule data becoming a first-class input to AI-driven remediation.
CrowdSec 1.8 Adds WAF Bot Detection and a Kubernetes Datasource
CrowdSec shipped version 1.8 with native bot detection for its WAF. The approach combines browser fingerprinting with proof of work, forcing bots to spend compute and raising the economics of scraping, scalping, and distributed attacks. It is live for nginx and openresty bouncers, with more on the way. A dedicated Kubernetes datasource lets one instance monitor many pods. This is a solid open-source WAF upgrade targeting the bot problem that plain signature rules keep missing.
Also notable
- BleepingComputer covers the same All-in-One Migration backup flaw from a different angle
- WordPress sites targeted via MiniOrange plugin vulnerabilities
WAFplanet take
This week is a reminder that WordPress remains the biggest attack surface in web security. Two popular plugins in a row highlight that patch timelines and installation counts never align. Virtual patching from a WAF or security plugin is the only way to close that gap at scale.
On the vendor side, both Cloudflare and CrowdSec are pushing WAF intelligence forward, one toward AI workflow, the other toward bot economics. Expect WAF products to keep absorbing capabilities the market used to buy separately.
We also read
- Imunify turns WAF for WordPress on by default across 1 million sites
- Imunify ships a new L7 rate limiter for abusive clients
- Fastly adds API enforcement to next-gen WAF
- Sucuri on the risk of third-party scripts, tags, and pixels
- Sucuri shares an August vulnerability and patch roundup
- Wordfence Intelligence weekly WordPress vulnerability report
- Prophaze lists top WAF options in Saudi Arabia
- Help Net Security covers new infosec products of the week