← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 28, 2026 · 07:54via CyberPress

Critical WPMU DEV Dashboard Flaw Can Lead to WordPress Remote Code Execution

Brief

A critical authentication bypass vulnerability in the WPMU DEV Dashboard plugin could allow unauthenticated attackers to obtain administrator access to vulnerable WordPress sites and potentially execute arbitrary code.

Tracked as CVE-2026-76581 , the flaw has a CVSS score of 9. 8 and affects WPMU DEV Dashboard versions 5.

  • 1 and earlier. The plugin, used on an estimated 350,000 WordPress sites, has been patched in version 5.
  • 2.

The vulnerability was discovered by Wordfence researcher Alex Thomas on August 19 during internal research aided by the company’s Argus vulnerability-discovery system.

Critical WPMU DEV Dashboard Flaw

Exploitation requires the target WordPress site to be connected to WPMU DEV, have Hub Single Sign-On enabled, and map the Hub SSO account to a WordPress administrator.

Read more on CyberPress