


Perceptive Security
SOC/SIEM Consultancy

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and …
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 18:01:32
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
The WPMU DEV Dashboard plugin for WordPress contains a critical authentication bypass vulnerability affecting all versions up to and including 5.0.1. The flaw stems from inconsistent HMAC message construction between two unauthenticated AJAX actions, wdpsso_step1 and wdpsso_step2. Step 1 signs an unseparated concatenation of token, state, redirect, and domain values, while step 2 verifies a concatenation that omits the domain field. An unauthenticated attacker can obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field. This results in the attacker gaining an authenticated administrator session. The vulnerability is exploitable only on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator account.
Technical details
Mitigation steps:
Affected products:
WPMU DEV Dashboard plugin for WordPress (versions up to and including 5.0.1)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-76581
https://wpmudev.com/project/wpmu-dev-dashboard/
https://www.wordfence.com/threat-intel/vulnerabilities/id/3d4321c8-15a4-46f5-9b0e-2098a7fcfb5b?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
