WORDPRESS · AUGUST 2026 · EARLY WARNING

WPMU DEV Dashboard WordPress Plugin Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
wpmu-dev-dashboard (wordpress)
Patched version
Not yet available
CVE-2026-76581

An early warning has been issued for a critical vulnerability in the WPMU DEV Dashboard plugin for WordPress. Users of affected versions should take immediate action.

What happened

An early warning has been issued regarding a critical vulnerability in the WPMU DEV Dashboard plugin for WordPress. This vulnerability, tracked as CVE-2026-76581, allows for an authentication bypass. An unauthenticated attacker could exploit this flaw to obtain a valid HMAC and replay it to gain an authenticated administrator session. This issue affects all versions of the plugin up to, and including, 5.0.1.

The vulnerability was first flagged on August 28, 2026. It is currently under investigation and has not been reported as exploited in the wild. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Users are advised to review their plugin versions and take necessary actions to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If wpmu-dev-dashboard is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using the WPMU DEV Dashboard plugin for WordPress in versions up to, and including, 5.0.1.

What should I do right now?

Upgrade the WPMU DEV Dashboard plugin to a version beyond 5.0.1 and review administrator sessions for any suspicious activity.

Has an official fix been released?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats