WPMU DEV Dashboard WordPress Plugin Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- wpmu-dev-dashboard (wordpress)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the WPMU DEV Dashboard plugin for WordPress. Users of affected versions should take immediate action.
What happened
An early warning has been issued regarding a critical vulnerability in the WPMU DEV Dashboard plugin for WordPress. This vulnerability, tracked as CVE-2026-76581, allows for an authentication bypass. An unauthenticated attacker could exploit this flaw to obtain a valid HMAC and replay it to gain an authenticated administrator session. This issue affects all versions of the plugin up to, and including, 5.0.1.
The vulnerability was first flagged on August 28, 2026. It is currently under investigation and has not been reported as exploited in the wild. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Users are advised to review their plugin versions and take necessary actions to mitigate potential risks.
What to do about it
- Upgrade the WPMU DEV Dashboard plugin to a version beyond 5.0.1.
- Review administrator sessions for any suspicious activity.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
How 0Day would have caught this
wpmu-dev-dashboard is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using the WPMU DEV Dashboard plugin for WordPress in versions up to, and including, 5.0.1.
What should I do right now?
Upgrade the WPMU DEV Dashboard plugin to a version beyond 5.0.1 and review administrator sessions for any suspicious activity.
Has an official fix been released?
No official fix has been published yet. Monitor the primary sources for updates.