Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-76581: WPMU DEV Dashboard plugin lets attackers log in as admin
CVE-2026-76581 · published 6 days ago
Summary
WordPress sites that use the WPMU DEV Dashboard plugin version 5.0.1 or earlier are at risk. Because of a flaw in how the plugin validates login requests, someone without credentials can trick the system into creating an administrator session. Update the plugin to the latest release (or remove it if you don't need it) and review admin accounts for any unexpected activity.
Original advisory text
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction b...
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published28 Aug 2026
Updated30 Aug 2026
First seen28 Aug 2026
Sources
CVE-2026-76581 · NVD
Monitor software like this
Free during beta